Windows Zero-Day "LegacyHive" Enables Hackers to Gain Admin Access

A security researcher operating under the handle "Nightmare Eclipse" releases a Windows zero-day exploit called LegacyHive that targets a vulnerability in the Windows User Profile Service. The exploit allows attackers to escalate privileges on fully patched Windows systems, though it currently lacks an official CVE identifier. Nightmare Eclipse publishes the proof-of-concept just hours after Microsoft's July 2026 Patch Tuesday updates.

Unlike previous exploits from the same researcher, the LegacyHive proof-of-concept deliberately requires additional user credentials, making it harder for casual attackers to weaponize. Security analysts who test the exploit confirm it works as described. Will Dormann of Tharros explains that successful exploitation lets non-admin users modify the classes registry hive, potentially gaining code execution when an administrator logs in.

Microsoft acknowledges the reported vulnerability and states it is actively investigating the claims. Cybersecurity expert Kevin Beaumont verifies the exploit and releases detection queries for Microsoft Defender for Endpoint users. The company says it remains committed to patching impacted products as quickly as possible once the investigation concludes.

Read More at the original source →