logo

LegacyHive: Video demo and analysis of Windows 0-day from NightmareEclipse

ID: 94dd3ee0-5636-5f6d-8bc9-1f13c53e5621

STIX ID: report--94dd3ee0-5636-5f6d-8bc9-1f13c53e5621

Feed Name: ThreatLocker Blog

Threat Score
55/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

NightmareEclipse published LegacyHive, a proof-of-concept exploit that leverages Object Manager symbolic links and manipulated profile hive paths to mount another user's UsrClass.dat hive on fully patched Windows systems; while the PoC is incomplete and not immediately weaponized to reveal passwords or execute privileged code, it demonstrates a path-resolution vulnerability affecting desktop and server installations, provides IOCs and detection guidance, and recommends auditing and monitoring of profile hive access and related API/event activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.