Microsoft fixes the Windows zero-day vulnerability LegacyHive

Microsoft fixes the Windows zero-day vulnerability LegacyHive

Windows

Microsoft has released security patches to address a Windows zero-day vulnerability called “LegacyHive,” which was discovered after Patch Tuesday in July 2026.

The vulnerability was discovered by a security researcher who uses the handle “Nightmare Eclipse” in protest against Microsoft’s bug bounty and vulnerability disclosure practices.

Nightmare Eclipse released a LegacyHive proof-of-concept (PoC) exploit a few hours after releasing security updates for July 2026 Patch Tuesday. claim It exploits a vulnerability in the Windows User Profile Service.

Picture

However, unlike previous exploits they have released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.

“Microsoft is aware of the reported security vulnerability and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson told BleepingComputer when asked for comment on LegacyHive.

Vulnerability analyst Will Dormann explained that non-admin users can use the Nightmare Eclipse exploit to modify the registry structure of classes and obtain automatic code execution when the administrator account logs into a compromised system.

One day after the PoC was published, cybersecurity expert Kevin Beaumont also spoke up published LegacyHive exploit detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.

Official LegacyHive patches available

Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and is now tracking it as CVE-2026-62832. However, Nightmare Eclipse has yet to confirm that it discovered the bug, instead labeling it as reported by an anonymous researcher.

The company states that LegacyHive is due to improper link resolution prior to file access (“link following”) in the Windows User Profile service, and successful exploitation allows local attackers to gain administrative privileges.

“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive,” Microsoft says. “A successful exploitation could allow the attacker to access or modify another user’s data and gain administrative privileges. No user interaction is required.”

ACROS Security, the company behind the cybersecurity platform 0Patch, also released free unofficial LegacyHive patches on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.

Nightmare Eclipse has uncovered several zero-day vulnerabilities since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma and Remove defense in Microsoft Defender, BitLocker and other Windows components.

Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities as part of Patch Tuesday in June 2026 and the RoguePlanet vulnerability in July, but the other zero-days are still awaiting an official patch.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *