Security Research 'Chaotic Eclipse' released a proof-of-concept exploit named LegacyHive, which targets a Windows User Profile Service vulnerability. It is an elevation of privilege flaw, and it allows attackers to gain Administrator access from a normal user. The current, public one requires initial credentials, however the earlier, more dangerous one didn't need any initial credentials. This is another step in the feud between the security researcher and Microsoft, and it follows previous vulnerability and PoC releases that exposed Microsoft Active Defender flaws. LegacyHive was released amidst another Windows patch of 622 flaws, including two in SharePoint Server and Active Directory that the US CISA has said need to be patched immediately.