Windows LegacyHive zero-day flaw gets free, unofficial patches

A recently disclosed Windows zero-day flaw has been patched by a cybersecurity company, even though Microsoft hasn’t yet released an official fix. The vulnerability, dubbed LegacyHive, allows attackers to escalate privileges on up-to-date Windows systems and gain automatic code execution when an admin account logs in.

The issue was found by a security researcher using the handle Nightmare Eclipse in the Windows User Profile Service. A stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue was also disclosed by Nightmare Eclipse, together with Microsoft’s July 2026 Patch Tuesday updates. However, this exploit can still be used by attackers to modify the classes registry hive and gain automatic code execution.

According to cybersecurity expert Kevin Beaumont, a non-admin user can exploit LegacyHive to extract stored secrets or modify any values in another user’s registry, which could affect what gets executed when they log in. This vulnerability doesn’t affect systems running Windows versions older than Windows 10 2004 and Windows Server 2019.

ACROS Security has made free, unofficial patches available for the LegacyHive vulnerability using its 0Patch platform. These micropatches inject code instructions to replace the vulnerable section of code and are designed to prevent attackers from exploiting the flaw even if they have already compromised a system. To install the patch on your Windows systems, you need to register a 0patch account and install the 0Patch agent.

It’s worth noting that Nightmare Eclipse has disclosed zero-day exploits for vulnerabilities in Microsoft Defender, BitLocker, and various Windows components in recent months. While some of these flaws have been fixed by Microsoft, others are still waiting for patches.

Microsoft is aware of the reported vulnerability and is actively investigating its validity and potential applicability. The company’s spokesperson stated that they are committed to investigating security issues and updating impacted products to protect customers as soon as possible.

The availability of free, unofficial patches highlights the importance of staying vigilant in the face of unpatched vulnerabilities. It also demonstrates how cybersecurity companies can step in to fill the gap when official fixes are not yet available.

For Windows users, this incident serves as a reminder to regularly review and update their systems’ security settings to prevent potential attacks. If you’re unsure about your system’s vulnerability or patch status, consider consulting with a trusted IT professional or using tools like Microsoft Defender for Endpoint to detect exploitation attempts.


Source: Bleeping Computer — 2026-07-21