Unofficial patch fixes Windows LegacyHive zero-day flaw

▼ Summary
– A Windows zero-day vulnerability, LegacyHive, allows privilege escalation on updated Windows systems via the User Profile Service.
– Non-admin users can exploit the flaw to modify the classes registry hive, enabling automatic code execution when an admin logs in.
– Microsoft is investigating the vulnerability but has not assigned a CVE-ID or released a security update.
– ACROS Security provides free unofficial micropatches for Windows 10 2004 or later and Windows Server 2022 or later via the 0Patch platform.
– The researcher, Nightmare Eclipse, has disclosed multiple zero-day exploits in recent months, with some fixed but others still unpatched.
Free unofficial patches have been released to address a newly disclosed Windows zero-day vulnerability that allows attackers to escalate privileges on fully updated systems. Tracked internally as LegacyHive, the flaw currently lacks a CVE identifier but poses a serious risk to Windows users.
The vulnerability was discovered by a security researcher operating under the alias Nightmare Eclipse within the Windows User Profile Service. The researcher publicly disclosed the flaw on the same day Microsoft rolled out its July 2026 Patch Tuesday updates, including a stripped-down proof-of-concept exploit designed to prevent threat actors from easily weaponizing it.
After reviewing the PoC, Tharros principal vulnerability analyst Will Dormann explained that non-admin users could exploit LegacyHive to modify the classes registry hive. This allows them to gain automatic code execution when an administrator logs into the compromised device. Cybersecurity expert Kevin Beaumont confirmed the exploit works just one day after the PoC was released and published detection queries for Microsoft Defender for Endpoint.
In response to inquiries from BleepingComputer, a Microsoft spokesperson stated: “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible.”
While Microsoft has yet to assign a CVE-ID or release official security updates, unofficial patches are already available from ACROS Security, the company behind the 0Patch cybersecurity platform. ACROS Security CEO Mitja Kolsek explained that the vulnerability allows a regular non-admin user to mount any other user’s registry hive in full access mode. This could enable extraction of stored secrets or modification of registry values to affect what executes when the target user logs in next.
Kolsek added: “With 0patch enabled, the exploit still seems to work, but it loads a temporary user profile hive instead of that from adminuser. Loading a temporary user profile hive is of no use to the attacker.”
The security flaw does not affect systems running Windows versions older than Windows 10 2004 and Windows Server 2019. ACROS Security provides micropatches for Windows 10 2004 or later and Windows Server 2022 or later. To install the free micropatch, users must register a 0patch account and install the 0Patch agent. If no custom patching policies block it, the patch deploys automatically without requiring a system restart.
Nightmare Eclipse has disclosed zero-day exploits for vulnerabilities in Microsoft Defender, BitLocker, and various Windows components in recent months. These include RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. Microsoft fixed YellowKey, GreenPlasma, and MiniPlasma in the June 2026 Patch Tuesday updates, and RoguePlanet in the July security updates. However, the other security issues disclosed by Nightmare Eclipse remain unpatched.
(Source: BleepingComputer)
