A security researcher known as “Nightmare Eclipse” has unveiled a new Windows zero-day exploit named LegacyHive, which enables attackers to escalate privileges on modern Windows systems.
Shortly after Microsoft released its July 2026 Patch Tuesday update, Nightmare Eclipse published a proof-of-concept (PoC) exploit. This exploit leverages a security vulnerability within the Windows User Profile Service, which has yet to be assigned a CVE ID for easier tracking.
Notably, unlike prior exploits from Nightmare Eclipse, the LegacyHive PoC has been altered to require additional user credentials, complicating the exploitation process for attackers.
“The PoC requires additional standard user credentials and a third username (which may also be an administrator account). A successful execution of the PoC will result in the target user hive being mounted at the root of the current user class,” the researchers clarified. Source.
“The original PoC did not necessitate any added user credentials and was unrestricted to the usrclass.dat hive. This vulnerability could potentially be exploited to load any hive, but it would require substantial skill to manipulate the PoC accordingly.”
Will Dormann, Principal Vulnerability Analyst at Tharros, analyzed the LegacyHive exploit and stated that a successful exploit could allow a non-administrator to modify the class registry hive, enabling code execution upon logging into a compromised system with an administrator account.
“For example, you can link the .txt file you open with calc.exe,” Dormann explains. “A savvy attacker can easily manipulate this for more intricate actions that do not necessitate user interaction.”
One day post-publication of the PoC, cybersecurity expert Kevin Beaumont confirmed that the exploit works effectively and has published detection queries for the LegacyHive exploit for use in Microsoft Defender for Endpoint (MDE) and other enterprise security platforms.
“Microsoft is aware of these reported vulnerabilities and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson informed BleepingComputer. “Microsoft is dedicated to promptly addressing security issues to protect our customers.”
“Importantly, we advocate for coordinated vulnerability disclosure, an industry standard that safeguards our customers while supporting researchers by ensuring findings undergo thorough investigation before becoming public.”
In recent months, Nightmare Eclipse has disclosed multiple zero-day exploits affecting various Windows components, including Microsoft Defender, BitLocker, and vulnerabilities like RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, and UnDefend.
Last month, Microsoft addressed the GreenPlasma, MiniPlasma, and YellowKey vulnerabilities in its June 2026 Patch Tuesday update and resolved the RoguePlanet issue during the July security update.
Microsoft responded to the revelations by Nightmare Eclipse, warning of possible legal actions against individuals engaging in malicious activities causing significant harm to customers. Cybersecurity experts suggest that the company might be directly threatening security researchers.
Updated July 17, 10:05 EDT: Added Microsoft statement.
Security teams document 54% of successful attacks and warn on only 14%. The rest operate invisibly within the environment.
Picus’ whitepaper illustrates how to test SIEM and EDR rules through breach and attack simulations to ensure undetected threats.
Source: www.bleepingcomputer.com




