NG Solution Team
Cybersecurity

LegacyHive: Microsoft issues August patches for Windows zero-day

Microsoft released security updates in its August Patch Tuesday to fix a Windows zero-day vulnerability called “LegacyHive”, now tracked as CVE-2026-62832. The flaw was disclosed after the July 2026 Patch Tuesday and prompted public proof-of-concept activity.

LegacyHive details and Microsoft response

Hours after the July updates, a researcher using the “Nightmare Eclipse” handle published a LegacyHive proof-of-concept (PoC), saying the handle was used in protest of Microsoft’s bug bounty and vulnerability disclosure practices. Unlike some earlier releases by the same researcher, the LegacyHive PoC requires additional credentials, which the researcher said makes it harder for threat actors to weaponize the issue.

A Microsoft spokesperson said, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims.” Microsoft has now patched the vulnerability as part of the August Patch Tuesday updates and tracks it as CVE-2026-62832, but the company has not acknowledged Nightmare Eclipse as the reporter and instead flagged the issue as reported by an anonymous researcher.

Microsoft says that LegacyHive stems from improper link resolution before file access (‘link following’) in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges. “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive,” Microsoft says. “Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required.”

Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse’s exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system. Cybersecurity expert Kevin Beaumont published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.

Mitigation and related activity

Third-party ACROS Security released free unofficial LegacyHive patches on July 20 for systems running Windows 10 version 2004 or later and Windows Server 2022 or later. Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and other Windows components.

Microsoft patched YellowKey, GreenPlasma, and MiniPlasma as part of the June 2026 Patch Tuesday and fixed RoguePlanet in July; the other disclosed zero-days listed by the researcher remain awaiting an official patch.

Related posts

Is Microsoft Racing to Patch a Critical Windows Defender Vulnerability?

James Smith

GeoServer Zero-Day Exploited Within Hours of Disclosure

Jessica Williams

Is Microsoft racing to fix a critical Defender flaw called RoguePlanet?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy