Windows LegacyHive Zero-Day Flaw Fixed by Free Unofficial Patches

www.news4hackers.com-windows-legacyhive-zero-day-flaw-fixed-by-free-unofficial-patches-windows-legacyhive-zero-day-flaw-fixed-by-free-unofficial-patches

Unofficial patches have been released to address a newly identified Windows zero-day vulnerability that enables privilege escalation on fully updated systems.

Windows Legacy Hive Zero-Day Flaw Receives Free, Unofficial Patches

The flaw, named LegacyHive and lacking a CVE identifier for tracking, was discovered by a security researcher utilizing the “Nightmare Eclipse” handle within the Windows User Profile Service. The vulnerability was disclosed on the same day Microsoft issued its July 2026 Patch Tuesday updates, accompanied by a stripped-down proof-of-concept exploit aimed at complicating its use in malicious attacks.

Analysis of the Proof-of-Concept

Analysis of the proof-of-concept by Tharros vulnerability analyst Will Dormann revealed that non-administrator users could exploit LegacyHive to alter the classes registry hive, enabling automatic code execution when an administrator account logs into an infected device. Cybersecurity researcher Kevin Beaumont confirmed the exploit’s functionality one day after the proof-of-concept was made public and shared detection queries for Microsoft Defender for Endpoint.

Microsoft Acknowledged the Reported Vulnerability

Microsoft acknowledged the reported vulnerability and stated it is investigating its validity and potential impact. A spokesperson emphasized the company’s commitment to addressing security issues and updating affected products to safeguard users.

Unofficial mitigation options: Despite Microsoft not yet assigning a CVE-ID or releasing official updates, ACROS Security, operator of the 0Patch platform, has provided free micropatches to counter the LegacyHive flaw.

Unofficial Mitigation Options

The vulnerability allows non-admin users to access any user’s registry hive with full permissions, enabling extraction of stored secrets or modification of registry values to influence execution upon subsequent logins. With 0Patch enabled, the exploit remains functional but loads a temporary user profile hive instead of the administrator’s. This temporary profile offers no utility to attackers, according to ACROS Security CEO Mitja Kolsek.

Applicability of Micropatches

The micropatches are applicable to Windows 10 2004 and later, as well as Windows Server 2022 and newer versions. The flaw does not affect systems running Windows 10 2004 or Windows Server 2019 and older.

Instructions for Deployment

Instructions for deploying the free micropatch are available through Nightmare Eclipse, which has previously disclosed zero-day exploits targeting Microsoft Defender, BitLocker, and other Windows components. Recent vulnerabilities attributed to Nightmare Eclipse include RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.

Microsoft’s Response and Ongoing Efforts

Microsoft resolved the YellowKey, GreenPlasma, and MiniPlasma issues in June 2026 updates and addressed RoguePlanet in July. Other vulnerabilities disclosed by the researcher remain unpatched. Security teams report that 54% of successful attacks go undetected, with only 14% triggering alerts. A whitepaper from Picus details how breach and attack simulation tests SIEM and EDR rules to prevent threats from bypassing detection.

Conclusion

Unofficial patches for LegacyHive are available to mitigate risks while official fixes are developed. The situation underscores the need for continuous monitoring and rapid response to evolving threats.



About Author

en_USEnglish