- A researcher released exploit code enabling low-privilege Windows accounts to modify admin accounts.
- The exploit, HiveLegacy, targets a Windows User Profile Service vulnerability and allows unauthorized registry changes.
- It requires knowledge of another user's credentials and a third account's username on the same machine.