A researcher has publicly disclosed an unpatched Windows flaw that can let one user access another user’s profile data with elevated privileges. The issue, dubbed LegacyHive, affects the Windows User Profile Service and is a local privilege-escalation bug that can load another user’s registry hive, including an administrator’s usrclass.dat, on systems running Microsoft’s July 2026 patches. The released proof-of-concept was intentionally stripped down, but the researcher says the fuller exploit could do more and originally did not require another user’s credentials.
Why it matters: Windows defenders now have another public zero-day to track even though Microsoft has not acknowledged or patched it yet. Organizations should watch for abuse of the User Profile Service, restrict local access where possible, and prioritize detection because prior Nightmare Eclipse disclosures were later exploited.
Sergiu Gatlan
2026.07.17
97% relevant
This article is a direct report on the same LegacyHive Windows User Profile Service zero-day, adding details that the public PoC was intentionally limited, that exploitation can modify the classes registry hive for code execution when an admin logs in, and that Microsoft Defender for Endpoint detection queries were published.
Ionut Arghire
2026.07.16
100% relevant
This article appears to be the first concrete report in the set on the newly disclosed LegacyHive Windows zero-day, establishing a distinct story separate from earlier Nightmare Eclipse disclosures such as YellowKey, GreatXML, and RoguePlanet.
← Back to all stories