Microsoft Patches 'LegacyHive' Zero-Day Amid Researcher's Ongoing Protest
Microsoft has released urgent security patches to address 'LegacyHive,' a Windows zero-day vulnerability. Disclosed by the researcher known as **Nightmare Eclipse**, the flaw allows local privilege escalation, highlighting ongoing tensions around vulnerability disclosure practices and bug bounty programs.

**Microsoft** has rolled out critical security updates to mitigate a **Windows** zero-day vulnerability, dubbed "**LegacyHive**," following its public disclosure post-July 2026 Patch Tuesday.
The flaw was revealed by a security researcher operating under the pseudonym **Nightmare Eclipse**, who has consistently used public disclosures to protest **Microsoft**'s bug bounty and vulnerability handling policies.
### LegacyHive: A Deeper Look
**Nightmare Eclipse** published a proof-of-concept (PoC) exploit for **LegacyHive** just hours after the July 2026 Patch Tuesday updates. The researcher claimed the exploit targets a vulnerability within the **Windows User Profile Service**.
While the PoC demonstrates the exploit's viability, it notably requires additional credentials, making its weaponization by threat actors more challenging compared to previous disclosures from **Nightmare Eclipse**.
**Microsoft** initially acknowledged awareness of the reported vulnerability, stating they were "actively investigating the validity and potential applicability of these claims."
Vulnerability analyst **Will Dormann** elaborated on the exploit's mechanics, explaining that non-administrative users could leverage **Nightmare Eclipse**'s PoC to modify the registry's classes hive. This modification could then grant automatic code execution when an administrator account logs into a compromised system.
Shortly after the PoC's release, cybersecurity expert **Kevin Beaumont** (known as **GossiTheDog**) published **LegacyHive** exploitation detection queries for **Microsoft Defender for Endpoint (MDE)** and independently confirmed the exploit's functionality.
### Official Patches and CVE-2026-62832
**Microsoft** has now officially patched the vulnerability as part of its August Patch Tuesday updates, tracking it as **CVE-2026-62832**. Interestingly, **Microsoft** has yet to credit **Nightmare Eclipse** for the discovery, instead attributing it to an anonymous researcher.
The company's advisory details that **LegacyHive** stems from improper link resolution before file access ('link following') within the **Windows User Profile Service**. Successful exploitation allows authenticated local attackers with credentials for another local account to run a specially crafted application. This can lead to loading another user's registry hive, providing access to or modification of user data, and ultimately, privilege escalation to administrator level. User interaction is not required for this exploit.
In the interim, **ACROS Security**, the company behind the **0Patch** cybersecurity platform, had already released free, unofficial **LegacyHive** patches on July 20 for systems running **Windows 10 2004** or later and **Windows Server 2022** or later.
### Nightmare Eclipse's Ongoing Disclosures
**Nightmare Eclipse** has been a prolific discloser of zero-day flaws since April 2026. Prior vulnerabilities include **ShieldBreak**, **RoguePlanet**, **YellowKey**, **BlueHammer**, **RedSun**, **GreenPlasma**, **MiniPlasma**, and **UnDefend**, impacting various **Microsoft** components such as **Microsoft Defender** and **BitLocker**.
While **Microsoft** patched **YellowKey**, **GreenPlasma**, and **MiniPlasma** in the June 2026 Patch Tuesday, and **RoguePlanet** in July, several other zero-days disclosed by **Nightmare Eclipse** are still awaiting official patches.