Microsoft patches LegacyHive Windows zero-day vulnerability

A recently disclosed Windows zero-day vulnerability, dubbed “LegacyHive,” has been patched by Microsoft as part of its August Patch Tuesday updates. The security flaw, which affects all supported versions of Windows, allows attackers to gain administrator privileges on compromised systems. This is particularly concerning given that the exploit requires only additional credentials from an attacker, making it easier for threat actors to weaponize.

The vulnerability was first disclosed by a security researcher using the “Nightmare Eclipse” handle, who published a proof-of-concept (PoC) exploit just hours after the July Patch Tuesday updates were released. Unlike previous exploits, however, this one requires additional credentials from an attacker, making it slightly more difficult for threat actors to exploit.

According to vulnerability analyst Will Dormann, non-admin users can use Nightmare Eclipse’s exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system. Cybersecurity expert Kevin Beaumont also confirmed that the exploit worked and published detection queries for Microsoft Defender for Endpoint (MDE).

Microsoft has now patched the vulnerability as part of its August Patch Tuesday updates, tracking it as CVE-2026-62832. However, despite acknowledging the flaw’s existence, the company has yet to give credit to Nightmare Eclipse, instead attributing the discovery to an anonymous researcher.

The LegacyHive vulnerability stems from improper link resolution before file access (‘link following’) in the Windows User Profile Service. Successful exploitation allows local attackers to gain administrator privileges and access or modify another user’s data.

While Microsoft’s patch is a welcome development, it’s worth noting that other security researchers have been working on unofficial patches for systems running Windows 10 2004 or later and Windows Server 2022 or later. ACROS Security released free patches for its 0Patch cybersecurity platform on July 20, highlighting the need for vigilance in the face of zero-day vulnerabilities.

This is not the first time Nightmare Eclipse has disclosed a zero-day flaw; since April 2026, they have revealed multiple vulnerabilities, including ShieldBreak and RoguePlanet. Microsoft has patched some of these flaws, but others are still awaiting an official fix.

In light of this vulnerability, it’s essential for users to ensure their systems are up-to-date with the latest security patches. As we’ve seen time and time again, zero-day vulnerabilities can have devastating consequences if left unaddressed. By prioritizing patching and staying informed about emerging threats, you can help protect your system from exploitation.

Practically speaking, this means keeping an eye on official patch releases and applying them promptly, especially for critical security updates like the LegacyHive patch. You should also be aware of any potential vulnerabilities in other Windows components, such as Microsoft Defender, BitLocker, or other services that may be exposed to similar zero-day flaws.


Source: Bleeping Computer — 2026-08-13