← All stories
● Covered by 4 sources · 5 reportsMedium impact

Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday

🔄 Updated 73d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • LegacyHive targets Windows User Profile Service.
  • Allows privilege escalation on updated systems.
  • Requires additional user credentials in PoC.
  • Released post-July 2026 Patch Tuesday.
  • Microsoft aware, investigating vulnerability.

Release of LegacyHive Zero-Day Exploit

Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, has published a new Windows zero-day exploit named LegacyHive. The release occurred soon after Microsoft's July 2026 Patch Tuesday, which contained a record number of security patches for Microsoft products.

Exploit Details and Functionality

LegacyHive exploits a vulnerability in the Windows User Profile Service, enabling attackers to escalate privileges from standard to administrator accounts. Chaotic Eclipse released the proof-of-concept (PoC) with added security measures requiring additional user credentials to limit its malicious use.

Compatibility and Risk Level

The exploit is applicable across all current versions of Windows, including systems updated with the latest patches. Despite being stripped down to prevent immediate exploitation, the LegacyHive vulnerability still poses risks for potential misuse and highlights the broader challenges in Microsoft's vulnerability management.

Unofficial patches have been released to mitigate the risk, as Microsoft is yet to assign a CVE or deploy an official fix.

Microsoft and Cybersecurity Industry Response

Microsoft has acknowledged the vulnerability and is investigating its impact and solutions. Security experts like Kevin Beaumont have confirmed its functionality, emphasizing the need for immediate detection and response strategies.

Free unofficial patches have been released to address the vulnerability, while Microsoft is deploying resources to validate the exploit and expedite necessary patches once confirmed.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Unofficial patches for the LegacyHive zero-day vulnerability in Windows are available, allowing non-admin users to escalate privileges. Microsoft is investigating the issue but has not yet released official fixes or assigned a CVE. This vulnerability poses a risk to current Windows systems, prompting immediate attention from users and security experts.

A new Windows zero-day exploit named LegacyHive permits privilege escalation on up-to-date systems. Developed by a security researcher, the exploit abuses a vulnerability in the Windows User Profile Service and complicates attacker access by requiring additional user credentials.

Nightmare Eclipse has released a new Windows zero-day exploit, named LegacyHive, which targets the User Profile Service allowing local privilege escalation. This poses significant risk as it can allow attackers access to other users’ profiles, including administrators, on systems updated with Microsoft’s July 2026 patches.

A researcher has released a Windows 0-day exploit allowing low-privilege accounts to elevate to admin rights. This follows Microsoft's record number of security patches, raising concerns about vulnerability management.

Security researcher Chaotic Eclipse released a proof-of-concept for a Windows vulnerability shortly after Microsoft's latest Patch Tuesday. The exploit targets the User Profile Service, allowing arbitrary hive loading, and is functional across all supported Windows versions, raising security concerns given its potential for exploitation.