Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, has published a new Windows zero-day exploit named LegacyHive. The release occurred soon after Microsoft's July 2026 Patch Tuesday, which contained a record number of security patches for Microsoft products.
LegacyHive exploits a vulnerability in the Windows User Profile Service, enabling attackers to escalate privileges from standard to administrator accounts. Chaotic Eclipse released the proof-of-concept (PoC) with added security measures requiring additional user credentials to limit its malicious use.
The exploit is applicable across all current versions of Windows, including systems updated with the latest patches. Despite being stripped down to prevent immediate exploitation, the LegacyHive vulnerability still poses risks for potential misuse and highlights the broader challenges in Microsoft's vulnerability management.
Unofficial patches have been released to mitigate the risk, as Microsoft is yet to assign a CVE or deploy an official fix.
Microsoft has acknowledged the vulnerability and is investigating its impact and solutions. Security experts like Kevin Beaumont have confirmed its functionality, emphasizing the need for immediate detection and response strategies.
Free unofficial patches have been released to address the vulnerability, while Microsoft is deploying resources to validate the exploit and expedite necessary patches once confirmed.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Unofficial patches for the LegacyHive zero-day vulnerability in Windows are available, allowing non-admin users to escalate privileges. Microsoft is investigating the issue but has not yet released official fixes or assigned a CVE. This vulnerability poses a risk to current Windows systems, prompting immediate attention from users and security experts.
A new Windows zero-day exploit named LegacyHive permits privilege escalation on up-to-date systems. Developed by a security researcher, the exploit abuses a vulnerability in the Windows User Profile Service and complicates attacker access by requiring additional user credentials.
Nightmare Eclipse has released a new Windows zero-day exploit, named LegacyHive, which targets the User Profile Service allowing local privilege escalation. This poses significant risk as it can allow attackers access to other users’ profiles, including administrators, on systems updated with Microsoft’s July 2026 patches.
A researcher has released a Windows 0-day exploit allowing low-privilege accounts to elevate to admin rights. This follows Microsoft's record number of security patches, raising concerns about vulnerability management.
Security researcher Chaotic Eclipse released a proof-of-concept for a Windows vulnerability shortly after Microsoft's latest Patch Tuesday. The exploit targets the User Profile Service, allowing arbitrary hive loading, and is functional across all supported Windows versions, raising security concerns given its potential for exploitation.