Microsoft corregge il Windows zero-day “LegacyHive” con le patch di agosto
Vulnerabilities

Illustrative image generated with AI

Microsoft Fixes “LegacyHive” Windows Zero-Day with August Patches

Microsoft patches LegacyHive zero-day CVE-2026-62832 in August updates, fixing privilege escalation in Windows User Profile Service. Apply now.

Text generated by artificial intelligence, published without human review. AI transparency

CVE-2026-62832 Allows Local Users to Gain Administrative Privileges

Microsoft addressed CVE-2026-62832, known as LegacyHive, in the August 2026 Patch Tuesday updates.

The flaw affects the Windows User Profile Service and how it handles links when accessing files. An authenticated local attacker with valid credentials for another account on the system can launch a specially crafted application.

The exploit allows the attacker to load another user’s Classes registry hive, read or modify its data, and configure code to execute automatically when an administrator logs on to the computer. No user interaction is required.

The vulnerability can therefore lead to administrative privilege escalation.

PoC Published After the July Updates

The flaw was disclosed after the July 2026 Patch Tuesday release. A researcher known as Nightmare Eclipse published a proof-of-concept exploit a few hours after the updates, criticizing Microsoft’s bug bounty and disclosure processes.

Microsoft formally credits the report to an anonymous researcher and does not recognize Nightmare Eclipse as the vulnerability’s discoverer.

The PoC requires additional credentials compared with other exploits published by the same researcher. This makes it less straightforward to turn into an operational attack tool, but does not eliminate the risk: security researcher Kevin Beaumont confirmed that it works.

Beaumont also published detection queries for Microsoft Defender for Endpoint (MDE) the day after the code was released.

Who Is Affected and Which Systems to Update

The affected systems are Microsoft Windows installations that include the Windows User Profile Service and the Classes registry hive. The brief does not provide a more detailed list of the specific affected builds.

Administrators should install the official August 2026 Patch Tuesday updates, which address CVE-2026-62832. They should also:

  • restrict and monitor the use of valid local credentials;
  • monitor changes to registry hives;
  • apply the available LegacyHive queries for Microsoft Defender for Endpoint;
  • investigate any suspicious activity involving the loading of another user’s hive.

Unofficial 0Patch Fixes Also Available

ACROS Security released free unofficial patches through 0Patch on July 20 for:

  • Windows 10 2004 and later;
  • Windows Server 2022 and later.

These fixes may provide temporary coverage, but they do not replace the Microsoft update once it is available.

LegacyHive is part of a series of zero-days disclosed by Nightmare Eclipse since April 2026: ShieldBreak, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend, affecting Microsoft Defender, BitLocker, and other Windows components. Microsoft already fixed YellowKey, GreenPlasma, and MiniPlasma in June 2026, as well as RoguePlanet in July 2026; no official patch is currently available for the others.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsMicrosoftWindowsLegacyHiveZero-DayPatch TuesdayCVE-2026-62832Security UpdatePrivilege Escalation
Back to home