Skip to content
Tech News
← Back to articles

Windows LegacyHive zero-day flaw gets free, unofficial patches

read original more articles
Why This Matters

The discovery of the LegacyHive zero-day flaw highlights the ongoing risks of privilege escalation vulnerabilities in Windows systems, emphasizing the importance of timely security updates. Unofficial patches from cybersecurity firms like ACROS Security provide critical protection for users until official fixes are released, underscoring the need for proactive security measures in the industry. This situation also demonstrates the value of independent security research in identifying and mitigating emerging threats.

Key Takeaways

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.

The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the "Nightmare Eclipse" handle in the Windows User Profile Service.

Nightmare Eclipse disclosed it the day Microsoft released its July 2026 Patch Tuesday updates, together with a stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue in attacks.

After analyzing the PoC, Tharros principal vulnerability analyst Will Dormann said that non-admin users can exploit LegacyHive to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised device.

Cybersecurity expert Kevin Beaumont also confirmed that the exploit works one day after the PoC was released and published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint.

"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the LegacyHive exploit.

"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible."

Free, unofficial patches available

While Microsoft has yet to assign a CVE-ID and release security updates to address the LegacyHive vulnerability, unofficial patches are already available from ACROS Security, the company behind the 0Patch cybersecurity platform.

"The vulnerability allows a regular non-admin user to mount any other user's registry hive in full access mode, and then either extract that user's stored secrets or modify any values in their registry to affect what gets executed the next time they log in," ACROS Security CEO Mitja Kolsek explains.

... continue reading