[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"project-93329":3},{"id":4,"name":5,"fullName":6,"owner":7,"repo":5,"description":8,"homepage":9,"htmlUrl":9,"language":10,"languages":9,"totalLinesOfCode":9,"stars":11,"forks":12,"watchers":13,"openIssues":14,"contributorsCount":15,"subscribersCount":15,"size":15,"stars1d":15,"stars7d":16,"stars30d":16,"stars90d":15,"forks30d":15,"starsTrendScore":17,"compositeScore":18,"rankGlobal":9,"rankLanguage":9,"license":19,"archived":20,"fork":20,"defaultBranch":21,"hasWiki":22,"hasPages":20,"topics":23,"createdAt":9,"pushedAt":9,"updatedAt":24,"readmeContent":25,"aiSummary":26,"trendingCount":15,"starSnapshotCount":15,"syncStatus":27,"lastSyncTime":28,"discoverSource":29},93329,"LegacyHive","MSNightmare\u002FLegacyHive","MSNightmare","N\u002FA",null,"C++",252,69,13,1,0,108,15,75.54,"MIT License",false,"main",true,[],"2026-07-22 04:02:08","# LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability\n\nThe PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root.\n\nThe PoC was stripped down as an attempt to prevent public exploitation, the original PoC did not require additional user credential and was not limited to usrclass.dat hive, any hive could be loaded using this vulnerability but you would need some brain cells to make the PoC do it.\n\n\u003Cimg width=\"1228\" height=\"627\" alt=\"Screenshot 2026-07-14 102705\" src=\"https:\u002F\u002Fgithub.com\u002Fuser-attachments\u002Fassets\u002F49deeaef-aadf-4a13-9006-a7c95eb2531e\" \u002F>\n\nThe PoC is fully functional in all currently supported desktop and server installation with July 2026 patch.\n\n","LegacyHive 是一个针对 Windows 用户配置文件服务（User Profile Service）中任意注册表配置单元（hive）加载漏洞（CVE-2026-XXXX，代号 MSNightmare）的概念验证（PoC）工具。它利用系统服务在加载 usrclass.dat 等用户 hive 时的权限校验缺陷，通过提供另一标准用户凭证及目标用户名，实现将任意用户（含管理员）的注册表 hive 挂载至当前会话的 HKCU\\ClassesRoot 下，从而达成提权。项目采用 C++ 实现，兼容所有已支持的 Windows 桌面与服务器版本（截至 2026 年 7 月补丁）。适用于安全研究、红队评估与漏洞复现等合规渗透测试场景，不适用于生产环境部署或恶意利用。",2,"2026-07-16 02:30:07","CREATED_QUERY"]