Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LegacyHive — Windows ProfSvc 0day | Kitploit
Tools/GitHubGitHub/msnightmare/legacyhive
Privilege EscalationVulnerability AnalysisExploitationPost-ExploitationPenetration TestingBinary Exploitation
GitHubmsnightmare/legacyhive

LegacyHive

Windows ProfSvc 0day

View Repository
2918531 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability

The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root.

The PoC was stripped down as an attempt to prevent public exploitation, the original PoC did not require additional user credential and was not limited to usrclass.dat hive, any hive could be loaded using this vulnerability but you would need some brain cells to make the PoC do it.

Screenshot 2026-07-14 102705

The PoC is fully functional in all currently supported desktop and server installation with July 2026 patch.

Download Tool