Microsoft patches LegacyHive Windows zero-day vulnerability

A Zero-Day Vulnerability in Windows User Profile Service Exposed by Security Researcher, Patched by Microsoft

In a recent revelation that highlights the ongoing cat-and-mouse game between security researchers and software developers, a Windows zero-day vulnerability known as “LegacyHive” has been discovered and subsequently patched by Microsoft. The flaw, which allows attackers to gain administrator privileges on compromised systems, was disclosed by a security researcher using the handle “Nightmare Eclipse” after the July 2026 Patch Tuesday updates were released.

The LegacyHive vulnerability is located in the Windows User Profile Service and can be exploited by attackers who have already gained access to a system with valid credentials. According to Will Dormann, a vulnerability analyst, non-admin users can use Nightmare Eclipse’s exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.

While the LegacyHive exploit requires additional credentials, making it harder for threat actors to weaponize the vulnerability, its very existence poses a significant risk to Windows users. Microsoft has now patched the flaw as part of its August Patch Tuesday updates and has assigned it the CVE-2026-62832 designation. However, in a somewhat unusual move, the company has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead attributing it to an anonymous researcher.

The LegacyHive vulnerability stems from improper link resolution before file access (‘link following’) in the Windows User Profile Service. Successful exploitation allows local attackers to gain administrator privileges, enabling them to access or modify another user’s data and potentially take control of a system. Microsoft emphasizes that user interaction is not required for successful exploitation, making it all the more concerning.

This is not the first time Nightmare Eclipse has disclosed a zero-day flaw in Windows components. Since April 2026, the security researcher has revealed multiple vulnerabilities, including ShieldBreak, RoguePlanet, and YellowKey, among others. While some of these flaws have been patched by Microsoft, others are still awaiting official patches.

The LegacyHive vulnerability serves as a reminder that even with regular patching and updates, zero-day exploits can still pose a significant threat to users. As the Blue Report 2026 highlights, once attackers gain valid credentials, prevention scores drop sharply, allowing them to take control of systems with relative ease. Users should remain vigilant and ensure they apply all available security patches to their Windows systems.

In light of this discovery, it is essential for users to prioritize regular patching and updates, as well as implement robust security measures, such as multi-factor authentication and network segmentation, to mitigate the risk of zero-day exploits like LegacyHive. By staying informed about vulnerabilities and taking proactive steps to secure their systems, users can reduce the likelihood of falling victim to sophisticated attacks.


Source: Bleeping Computer — 2026-08-13