Recently, a free, unofficial patch has surfaced for a critical Windows zero-day vulnerability dubbed LegacyHive, which enables attackers to escalate privileges on contemporary Windows systems.
This security flaw, lacking a CVE ID for easy tracking, was identified by security researchers under the alias Nightmare Eclipse within the Windows User Profile Service.
On the same day Microsoft released its July 2026 Patch Tuesday update, Nightmare Eclipse disclosed the existence of this flaw, highlighting that a proof-of-concept (PoC) exploit was removed to complicate potential attacks.
Will Dormann, lead vulnerability analyst at Tharros, stated that a non-administrator user could exploit the LegacyHive flaw to modify the class registry hive, potentially allowing malicious code to execute upon an administrator logging into a compromised device.
Cybersecurity expert Kevin Beaumont confirmed the functionality of the exploit just one day post-PoC release and also shared LegacyHive exploit detection queries for Microsoft Defender for Endpoint.
In response to inquiries about the LegacyHive vulnerability, a Microsoft spokesperson told BleepingComputer, “Microsoft is aware of the reported vulnerabilities and is actively investigating their validity and applicability.”
Furthermore, they stated, “Microsoft is dedicated to addressing this security concern and will update affected products rapidly to safeguard our customers.”
Free Unofficial Patch Now Available
While Microsoft has yet to assign a CVE ID or release an official security update for the LegacyHive vulnerability, a free unofficial patch is available through ACROS Security, leveraging their 0Patch cybersecurity platform.
According to ACROS Security CEO Mitja Kolsek, “This vulnerability allows a standard non-administrator user to mount another user’s registry hive with full access, enabling them to extract sensitive information or modify registry values that will affect the next login.”
“Although the exploit remains functional with 0Patch enabled, it targets the temporary user profile hive instead of the admin user, rendering it ineffective for attackers.”
This vulnerability impacts only systems running Windows 10 (version 2004 and later) and Windows Server 2019 or newer. ACROS Security’s micro patch works for these versions, providing essential protection.
To apply the free micropatch to your Windows system, register for a 0Patch account and install the 0Patch agent. If no custom patching policy blocks it, the micropatch will be automatically deployed without requiring a system reboot.
In recent months, Nightmare Eclipse has disclosed multiple zero-day exploits affecting Microsoft Defender, BitLocker, and various Windows components—including RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, and MiniPlasma. Visit this link to learn more.
Last month, Microsoft addressed the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities during its June 2026 Patch Tuesday update, while also resolving RoguePlanet in July. However, other vulnerabilities highlighted by Nightmare Eclipse remain without patches.
Security teams document only 54% of successful attacks and issue warnings on just 14%, leaving the rest undetected. Picus’ whitepaper outlines how to test your SIEM and EDR rules in breach and attack simulations to ensure threats are spotted.
Source: www.bleepingcomputer.com




