In brief: The LegacyHive vulnerability enables privilege escalation on Windows 10 2004+ and Windows Server 2022; an unofficial micropatch from ACROS Security is available, with an official CVE and update pending.
A zero-day vulnerability in the Windows User Profile Service allows attackers to gain administrator rights from user accounts. An unofficial micropatch is available via the 0patch platform, while Microsoft works on an official update.
Security researcher Nightmare Eclipse has disclosed a zero-day vulnerability in the Windows User Profile Service called LegacyHive. The vulnerability affects Windows 10 from version 2004 onwards and Windows Server 2022. Older Windows versions are not vulnerable. To date, Microsoft has provided neither a CVE number nor an official patch.
The vulnerability allows users without administrator rights to mount the registry structure of other user accounts with full access. Through this access, attackers can read stored login credentials or manipulate registry values so that malicious code is automatically executed the next time an administrator logs in. Mitja Kolsek, CEO of ACROS Security, describes the attack vector: A normal user can mount registry structures of any other user in full access mode and thus either extract secrets or change values to influence future logins.
ACROS Security has developed unofficial fixes via the 0patch platform. These so-called micropatches are small code instructions that replace the vulnerable program section in RAM. When the 0patch agent is enabled, the system loads a temporary user profile structure instead of the administrator structure when an attack is attempted, thereby preventing the privilege escalation. The patch requires no operating system restart.
Microsoft has confirmed that the reports are being investigated and the company is working on validation. In recent months, Nightmare Eclipse has disclosed several other zero-days in Windows components such as Microsoft Defender and BitLocker. Microsoft patched some of these vulnerabilities (YellowKey, GreenPlasma, RoguePlanet) in the June and July 2026 patch days; other published vulnerabilities remain without an official update for now.
Source: www.it-daily.net · Published 22 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.