Microsoft Patches LegacyHive Windows Zero-Day Vulnerability
Microsoft has released a security update for a Windows zero-day vulnerability known as LegacyHive. The flaw was disclosed shortly after the July 2026 Patch Tuesday updates and could allow an authenticated local attacker to gain administrative privileges.
The vulnerability was disclosed by a security researcher using the online handle “Nightmare Eclipse,” reportedly in protest of Microsoft’s bug bounty and vulnerability disclosure practices.
Hours after the July 2026 Patch Tuesday security updates were released, Nightmare Eclipse published a proof-of-concept (PoC) exploit for LegacyHive. The published exploit targets a security weakness in the Windows User Profile Service.
Unlike some of Nightmare Eclipse’s previous exploits, the LegacyHive PoC requires additional credentials. This requirement could make the Windows vulnerability more difficult for threat actors to exploit in real-world attacks.
In a statement to BleepingComputer, a Microsoft spokesperson said, “Microsoft is aware of the reported vulnerabilities and is actively investigating the validity and potential applicability of these claims.”
Vulnerability analyst Will Dormann explained that a non-administrator could use the Nightmare Eclipse exploit to modify the class registry hive. This could allow malicious code to run automatically when an administrator logs into a compromised Windows system.
One day after the proof-of-concept was released, cybersecurity expert Kevin Beaumont published LegacyHive detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit works.
Microsoft releases official LegacyHive security patch
Microsoft addressed the LegacyHive vulnerability as part of the August 2026 Patch Tuesday updates. The flaw is now tracked as CVE-2026-62832. Nightmare Eclipse has not acknowledged discovering the vulnerability and continues to credit an anonymous researcher for reporting it.
According to Microsoft, CVE-2026-62832 is caused by improper link resolution, also known as “link following,” in the Windows User Profile Service before a file is accessed. If successfully exploited, the flaw could allow a local attacker to obtain administrative privileges.
“An authenticated attacker with the credentials of another local account could run a specially crafted application to read another user’s registry hive,” Microsoft said. “A successful exploit could allow the attacker to access or modify another user’s data and gain administrative privileges. No user interaction is required.”
ACROS Security, the company behind the 0Patch security platform, released a free unofficial LegacyHive fix on July 20. The patch supports systems running Windows 10 version 2004 and later, as well as Windows Server 2022 and later.
Beginning in April 2026, Nightmare Eclipse said it would support exploits for ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and tools designed to remove or disable Microsoft Defender, BitLocker, and other Windows security components.
Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities in the June 2026 Patch Tuesday updates and fixed the RoguePlanet flaw in July. Other vulnerabilities disclosed by Nightmare Eclipse are reportedly still awaiting official Microsoft patches.
The overall prevention score can obscure what happens after initial access. If an attacker uses valid credentials, the effectiveness of your defenses can drop sharply.
Blue Report 2026 measures defensive techniques across different technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




