Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as 'LegacyHive' disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the 'Nightmare Eclipse' handle in protest of Microsoft'…
Intelligence analysis by Llama

Microsoft has patched the LegacyHive Windows zero-day vulnerability, which allows local attackers to gain administrator privileges. The vulnerability was disclosed by a security researcher who uses the 'Nightmare Eclipse' handle. The company has released security patches to address the issue.
Imagine you have a special key that can unlock any door in your house. But, the key only works if you have the right password. If you have the password, you can use the key to unlock the door and get inside. But, if you don't have the password, the key won't work. That's kind of like what's happening with the LegacyHive vulnerability. It's a special key that can unlock the Windows User Profile Service, but it only works if you have the right credentials. If you don't have the right credentials, the key won't work and you won't be able to get inside.
Analysis
LegacyHive Vulnerability Details
Microsoft has patched the LegacyHive Windows zero-day vulnerability, which allows local attackers to gain administrator privileges. The vulnerability was disclosed by a security researcher who uses the 'Nightmare Eclipse' handle. The company has released security patches to address the issue.
The LegacyHive vulnerability stems from improper link resolution before file access ('link following') in the Windows User Profile Service. Successful exploitation allows local attackers to gain administrator privileges. User interaction is not required.
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released. However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.
Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. However, it has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead tagging it as reported by an anonymous researcher.
ACROS Security, the company behind the 0Patch cybersecurity platform, also released free unofficial LegacyHive patches on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later. Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and other Windows components.
Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, and the RoguePlanet vulnerability in July, but the other zero-days are still awaiting an official patch.
Key points
- Microsoft has patched the LegacyHive Windows zero-day vulnerability.
- The vulnerability allows local attackers to gain administrator privileges.
- The vulnerability was disclosed by a security researcher who uses the 'Nightmare Eclipse' handle.
- ACROS Security released free unofficial patches for the vulnerability.
- Nightmare Eclipse has disclosed multiple zero-day flaws in Microsoft Defender, BitLocker, and other Windows components.
The fact that Microsoft has patched the LegacyHive vulnerability in a timely manner is a positive sign. It shows that the company is taking the issue seriously and is working to fix the problem. Additionally, the fact that ACROS Security released free unofficial patches for the vulnerability shows that the security community is working together to help protect users.
The fact that Nightmare Eclipse has disclosed multiple zero-day flaws in Microsoft Defender, BitLocker, and other Windows components is a cause for concern. It shows that the company's bug bounty and vulnerability disclosure practices are not effective in preventing these types of vulnerabilities from being disclosed. Additionally, the fact that the other zero-days are still awaiting an official patch is a sign that the company is not taking the issue seriously enough.



