logo

LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised

ID: fdbfebfc-677f-56f5-beb4-c81ccca968c6

STIX ID: report--fdbfebfc-677f-56f5-beb4-c81ccca968c6

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-23

...
...

LegacyHive is a Windows local privilege escalation zero-day published by the researcher known as NightmareEclipse that abuses the profsvc User Profile Service to mount other users' registry hives (including admin hives). The public proof‑of‑concept is intentionally limited—restricted to usrclass.dat and requiring credentials—but experts warn capable attackers could fill the gaps and weaponize the bug quickly; Microsoft is investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.