
Microsoft has launched safety patches to deal with a Home windows zero-day vulnerability referred to as “LegacyHive,” disclosed after the July 2026 Patch Tuesday.
The safety flaw was disclosed by a safety researcher who makes use of the “Nightmare Eclipse” deal with in protest of Microsoft’s bug bounty and vulnerability disclosure practices.
Nightmare Eclipse printed a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday safety updates have been launched, claiming it exploits a safety vulnerability within the Home windows Consumer Profile Service.
Nonetheless, not like earlier exploits they launched, the LegacyHive PoC requires extra credentials, making it tougher for risk actors to weaponize the vulnerability.
“Microsoft is conscious of the reported vulnerability and is actively investigating the validity and potential applicability of those claims,” a Microsoft spokesperson advised BleepingComputer when requested for a press release relating to LegacyHive.
Vulnerability analyst Will Dormann explained that non-admin customers can use Nightmare Eclipse’s exploit to switch the courses registry hive and achieve automated code execution when the admin account logs in to a compromised system.
Someday after the PoC was launched, cybersecurity knowledgeable Kevin Beaumont additionally published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.
Official LegacyHive patches obtainable
Microsoft has now patched the vulnerability this week as a part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. Nonetheless, it has but to acknowledge that Nightmare Eclipse found the flaw, as a substitute tagging it as reported by an nameless researcher.
The corporate says that LegacyHive stems from improper hyperlink decision earlier than file entry (‘hyperlink following’) within the Home windows Consumer Profile Service, and profitable exploitation permits native attackers to achieve administrator privileges.
“An authenticated attacker who has credentials for an additional native account might run a specifically crafted utility to load one other person’s registry hive,” Microsoft says. “Profitable exploitation might enable the attacker to entry or modify one other person’s knowledge and achieve administrator privileges. Consumer interplay will not be required.”
ACROS Safety, the corporate behind the 0Patch cybersecurity platform, additionally released free unofficial LegacyHive patches on July 20 for techniques operating Home windows 10 2004 or later and Home windows Server 2022 or later.
Nightmare Eclipse has disclosed a number of zero-day flaws since April 2026, together with ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and different Home windows elements.
Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as a part of the June 2026 Patch Tuesday, and the RoguePlanet vulnerability in July, however the different zero-days are nonetheless awaiting an official patch.
General prevention scores can conceal what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses method by method throughout 338 million simulations run in buyer manufacturing environments.

