Windows LegacyHive zero-day flaw gets free, unofficial patches

A newly discovered Windows zero-day flaw, dubbed LegacyHive, has left Microsoft scrambling to address the issue despite already releasing its July 2026 Patch Tuesday updates. The vulnerability allows attackers to escalate privileges on up-to-date Windows systems, putting millions of users at risk.

The bug was found by a security researcher using the handle Nightmare Eclipse in the Windows User Profile Service. To make it harder for threat actors to exploit this flaw, Nightmare Eclipse released a proof-of-concept (PoC) exploit that is designed to be stripped down and less effective on its own. However, after analyzing the PoC, cybersecurity experts have confirmed that non-admin users can indeed exploit LegacyHive to gain automatic code execution when the admin account logs into a compromised device.

The good news for affected Windows systems is that free, unofficial patches are already available from ACROS Security, the company behind the 0Patch platform. These micropatches inject small pieces of code to replace the vulnerable section of code in the Windows User Profile Service. According to ACROS Security CEO Mitja Kolsek, the vulnerability allows a non-admin user to mount any other user’s registry hive in full access mode, making it possible for attackers to extract secrets or modify values that will be executed the next time the user logs in.

While Microsoft has yet to assign a CVE-ID and release security updates to address LegacyHive, ACROS Security is offering micropatches specifically designed for Windows 10 2004 or later and Windows Server 2022 or later. To install these patches, users need to register a 0patch account and install the 0Patch agent, which will deploy the patch automatically without requiring a system restart.

It’s worth noting that Nightmare Eclipse has been instrumental in disclosing zero-day exploits for various Windows components in recent months, including RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While Microsoft has fixed some of these flaws, others are still waiting for a patch.

In light of this latest vulnerability, it’s clear that attackers are continuing to find ways to exploit Windows systems despite the efforts of security researchers and vendors like Microsoft. This highlights the importance of staying vigilant and taking proactive steps to protect against potential threats. For users who have been affected by LegacyHive, installing these free micropatches can provide an immediate layer of protection until a formal patch is released.

In fact, this situation underscores the need for regular security testing and validation to ensure that all layers of defense are working as intended. By test-driving your SIEM and EDR rules through breach and attack simulation tests, you can identify potential blind spots and prevent threats from slipping by detection.


Source: Bleeping Computer — 2026-07-21