LegacyHive Zero-Day: Unofficial Patches Emerge for Windows Privilege Escalation Flaw
A newly disclosed Windows zero-day vulnerability, dubbed **LegacyHive**, allows attackers to escalate privileges on modern Windows systems. While **Microsoft** investigates, free unofficial patches are now available, offering a stopgap solution for IT security professionals and privacy-conscious users.

Free unofficial patches are now available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
The vulnerability (dubbed **LegacyHive** and currently without a **CVE ID**) was discovered by a security researcher operating under the handle **Nightmare Eclipse**. The flaw resides within the Windows User Profile Service.
**Nightmare Eclipse** disclosed the vulnerability on the same day **Microsoft** released its July 2026 Patch Tuesday updates. They also provided a stripped-down proof-of-concept (PoC) exploit, intentionally designed to hinder immediate weaponization by threat actors.
### Understanding LegacyHive's Impact
After analyzing the PoC, **Tharros** principal vulnerability analyst **Will Dormann** confirmed that non-admin users can exploit **LegacyHive**. This allows them to modify the classes registry hive, leading to automatic code execution when an administrator account logs into a compromised device.
Cybersecurity expert **Kevin Beaumont** also confirmed the exploit's functionality shortly after the PoC release. He subsequently published **LegacyHive** exploitation detection queries for **Microsoft Defender for Endpoint**.
**Microsoft** has acknowledged the issue. A spokesperson stated, "**Microsoft** is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. **Microsoft** is committed to investigating security issues and updating impacted products to protect customers as soon as possible."
## Free, Unofficial Patches Available
While **Microsoft** has yet to assign a **CVE-ID** and release official security updates, unofficial patches are already available from **ACROS Security**, the company behind the **0Patch** cybersecurity platform.
**ACROS Security** CEO **Mitja Kolsek** explained the vulnerability: "The vulnerability allows a regular non-admin user to mount any other user's registry hive in full access mode, and then either extract that user's stored secrets or modify any values in their registry to affect what gets executed the next time they log in."
He added, "With **0patch** enabled, the exploit still seems to work, but it loads a temporary user profile hive instead of that from adminuser. Loading a temporary user profile hive is of no use to the attacker."
This security flaw does not affect systems running Windows versions older than Windows 10 2004 and Windows Server 2019. **ACROS Security** provides micropatches β small patches that inject code instructions to replace vulnerable sections β for Windows 10 2004 or later and Windows Server 2022 or later.
To install the free micropatch, users need to register a **0patch** account and install the **0Patch** agent. The patch will be deployed automatically without requiring a system restart, provided no custom patching policies block it.
### Nightmare Eclipse's Disclosure History
**Nightmare Eclipse** has a history of disclosing zero-day exploits across various **Microsoft** components, including **Microsoft Defender**, **BitLocker**, and other Windows elements. Recent disclosures include **RoguePlanet**, **BlueHammer**, **RedSun**, **YellowKey**, **GreenPlasma**, **MiniPlasma**, and **UnDefend**.
**Microsoft** addressed the **YellowKey**, **GreenPlasma**, and **MiniPlasma** flaws in the June 2026 Patch Tuesday updates, and the **RoguePlanet** vulnerability in the July security updates. However, other security issues disclosed by **Nightmare Eclipse** are still awaiting official patches.