logo

New Windows LegacyHive zero-day gives hackers admin privileges

ID: 53009131-bcb7-5167-90b7-ba3fd46e0e89

STIX ID: report--53009131-bcb7-5167-90b7-ba3fd46e0e89

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

A security researcher known as "Nightmare Eclipse" released a proof-of-concept called LegacyHive that exploits a previously unassigned Windows User Profile Service vulnerability to escalate privileges on up-to-date Windows systems by mounting and modifying user registry hives (usrclass.dat), enabling automatic code execution when an administrator logs in; the PoC was intentionally modified to require additional credentials, independent researchers confirmed the exploit and published detection guidance for Microsoft Defender for Endpoint, and Microsoft has warned of legal action related to such disclosures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.