Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Windows Enterprise and Server environments
Incident: Disclosure of a Windows zero-day PoC alongside active exploitation of SharePoint and ADFS vulnerabilities.
Impact: Attackers could achieve full system administrative privileges or bypass authentication on corporate servers.
Attacker: Unidentified threat actors and independent researchers
Analysis: The release of the LegacyHive PoC reveals a critical privilege escalation flaw in the Windows User Profile Service that remains functional despite recent updates. Concurrently, CISA has added critical SharePoint and ADFS vulnerabilities to its KEV catalog due to active exploitation. This trend indicates a volatile patching cycle where new vulnerabilities are surfacing faster than they can be effectively mitigated.
Recommendations: Prioritize patching for SharePoint Server and ADFS to mitigate known exploited flaws.; Monitor system logs for unauthorized attempts to mount user hives via the User Profile Service.; Enforce strict least-privilege access controls to limit the potential impact of local privilege escalation.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source