Illustrative image generated with AI
Microsoft Fixes “LegacyHive” Windows Zero-Day with August Patches
Microsoft patches LegacyHive zero-day CVE-2026-62832 in August updates, fixing privilege escalation in Windows User Profile Service. Apply now.
Text generated by artificial intelligence, published without human review. AI transparency
CVE-2026-62832 Allows Local Users to Gain Administrative Privileges
Microsoft addressed CVE-2026-62832, known as LegacyHive, in the August 2026 Patch Tuesday updates.
The flaw affects the Windows User Profile Service and how it handles links when accessing files. An authenticated local attacker with valid credentials for another account on the system can launch a specially crafted application.
The exploit allows the attacker to load another user’s Classes registry hive, read or modify its data, and configure code to execute automatically when an administrator logs on to the computer. No user interaction is required.
The vulnerability can therefore lead to administrative privilege escalation.
PoC Published After the July Updates
The flaw was disclosed after the July 2026 Patch Tuesday release. A researcher known as Nightmare Eclipse published a proof-of-concept exploit a few hours after the updates, criticizing Microsoft’s bug bounty and disclosure processes.
Microsoft formally credits the report to an anonymous researcher and does not recognize Nightmare Eclipse as the vulnerability’s discoverer.
The PoC requires additional credentials compared with other exploits published by the same researcher. This makes it less straightforward to turn into an operational attack tool, but does not eliminate the risk: security researcher Kevin Beaumont confirmed that it works.
Beaumont also published detection queries for Microsoft Defender for Endpoint (MDE) the day after the code was released.
Who Is Affected and Which Systems to Update
The affected systems are Microsoft Windows installations that include the Windows User Profile Service and the Classes registry hive. The brief does not provide a more detailed list of the specific affected builds.
Administrators should install the official August 2026 Patch Tuesday updates, which address CVE-2026-62832. They should also:
- restrict and monitor the use of valid local credentials;
- monitor changes to registry hives;
- apply the available LegacyHive queries for Microsoft Defender for Endpoint;
- investigate any suspicious activity involving the loading of another user’s hive.
Unofficial 0Patch Fixes Also Available
ACROS Security released free unofficial patches through 0Patch on July 20 for:
- Windows 10 2004 and later;
- Windows Server 2022 and later.
These fixes may provide temporary coverage, but they do not replace the Microsoft update once it is available.
LegacyHive is part of a series of zero-days disclosed by Nightmare Eclipse since April 2026: ShieldBreak, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend, affecting Microsoft Defender, BitLocker, and other Windows components. Microsoft already fixed YellowKey, GreenPlasma, and MiniPlasma in June 2026, as well as RoguePlanet in July 2026; no official patch is currently available for the others.
Sources
This article is an original reworking based on the sources below.
