A researcher has publicly disclosed an unpatched Windows flaw that can let one user access another user’s profile data with elevated privileges. The issue, dubbed LegacyHive, affects the Windows User Profile Service and is a local privilege-escalation bug that can load another user’s registry hive, including an administrator’s usrclass.dat, on systems running Microsoft’s July 2026 patches. The released proof-of-concept was intentionally stripped down, but the researcher says the fuller exploit could do more and originally did not require another user’s credentials.
Sergiu Gatlan
2026.08.13
97% relevant
This article updates the same LegacyHive event by reporting that Microsoft has now patched the Windows User Profile Service zero-day and assigned it CVE-2026-62832 in the August 2026 Patch Tuesday release.
2026.08.12
62% relevant
The article likely connects one of the publicly disclosed August zero-days, CVE-2026-62832, to the previously published LegacyHive proof of concept from Nightmare Eclipse, adding Microsoft’s apparent attribution and showing how that disclosure intersected with this month’s patch cycle.
Lawrence Abrams
2026.08.11
94% relevant
This article confirms Microsoft has now patched the previously disclosed LegacyHive issue as CVE-2026-62832 in the Windows User Profile Service as part of August 2026 Patch Tuesday.
Sergiu Gatlan
2026.07.17
97% relevant
This article is a direct report on the same LegacyHive Windows User Profile Service zero-day, adding details that the public PoC was intentionally limited, that exploitation can modify the classes registry hive for code execution when an admin logs in, and that Microsoft Defender for Endpoint detection queries were published.
Ionut Arghire
2026.07.16
100% relevant
This article appears to be the first concrete report in the set on the newly disclosed LegacyHive Windows zero-day, establishing a distinct story separate from earlier Nightmare Eclipse disclosures such as YellowKey, GreatXML, and RoguePlanet.