A security researcher using the 'Nightmare Eclipse' handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
Exploit Details
LegacyHive abuses a security vulnerability in the Windows User Profile Service, which has yet to receive a CVE ID for easier tracking. The exploit was published hours after Microsoft released its July 2026 Patch Tuesday updates.
Unlike previous exploits released by Nightmare Eclipse, the LegacyHive PoC has been modified to require additional credentials, making it harder for attackers to weaponize the vulnerability. The researcher explained that the PoC requires another standard user credentials and a third username, which can be an administrator account.
Exploitation and Impact
Successful exploitation would allow non-admin users to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised system. According to Will Dormann, principal vulnerability analyst at Tharros, clever attackers will easily be able to figure out how to do things that are more interesting and/or don't even require user interaction.
For example, as a novelty, attackers can associate .txt files to open with calc.exe. Cybersecurity expert Kevin Beaumont also confirmed that the exploit works and published LegacyHive exploitation detection queries for the Microsoft Defender for Endpoint (MDE) enterprise-grade endpoint security platform.
Microsoft Response
Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. A Microsoft spokesperson stated that the company is committed to investigating security issues and updating impacted products to protect customers as soon as possible.
Microsoft also emphasized its support for coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public.
Related Exploits and Disclosures
In recent months, Nightmare Eclipse has disclosed zero-day exploits for multiple Windows vulnerabilities in Microsoft Defender, BitLocker, and various Windows components, including RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.
Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey flaws last month as part of the June 2026 Patch Tuesday updates and the RoguePlanet vulnerability in the July security updates. The company's response to Nightmare Eclipse's disclosures has been met with warnings of legal action against people engaging in 'malicious activity causing real harm to our customers'.
Cybersecurity experts believe that Microsoft's response may be directly threatening the security researcher. The LegacyHive exploit is the latest in a series of zero-day exploits disclosed by Nightmare Eclipse, highlighting the ongoing struggle between security researchers and software vendors to identify and patch vulnerabilities before they can be exploited by attackers.
- Related Articles:
- Recently leaked Windows zero-days now exploited in attacks
- Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
- Windows BitLocker zero-day gives access to protected drives, PoC released
- Exploit available for new DirtyDecrypt Linux root escalation flaw
- Microsoft patches RoguePlanet Defender zero-day vulnerability
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Source: BleepingComputer