Skip to content
Tech News
← Back to articles

Microsoft patches LegacyHive Windows zero-day vulnerability

read original more articles
Why This Matters

The recent patch for the LegacyHive zero-day vulnerability highlights the ongoing importance of timely security updates in protecting Windows users from sophisticated exploits. It underscores the evolving threat landscape where even credential-restricted exploits can lead to privilege escalation, emphasizing the need for robust security practices for both consumers and the industry. Addressing such vulnerabilities promptly helps safeguard sensitive data and maintain trust in Windows-based systems.

Key Takeaways

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.

The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices.

Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service.

However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.

"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.

Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.

One day after the PoC was released, cybersecurity expert Kevin Beaumont also published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.

Official LegacyHive patches available

Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. However, it has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead tagging it as reported by an anonymous researcher.

The company says that LegacyHive stems from improper link resolution before file access ('link following') in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges.

... continue reading