Microsoft Finally Patches LegacyHive Windows Zero-Day


legacyhive fixed windows 11
Image credit: Microsoft

Microsoft has patched the LegacyHive Windows vulnerability through the August 2026 Patch Tuesday updates, as BleepingComputer writes. The flaw could allow a local attacker to gain administrator privileges without user interaction.

Tracked as CVE-2026-62832, the vulnerability affects the Windows User Profile Service. Microsoft fixed it alongside around 400 other security flaws addressed this month.

LegacyHive could let attackers access another user’s registry hive

LegacyHive stems from improper link resolution before file access in the Windows User Profile Service.

An attacker needs credentials for another local account before attempting exploitation. A specially crafted application can then load that user’s registry hive, allowing the attacker to read or modify data that should remain inaccessible.

Researcher Will Dormann demonstrated how an attacker could modify the classes hive and trigger code execution when an administrator signs in. Successful exploitation could ultimately elevate privileges to administrator level.

Researchers published a working proof-of-concept

Security researcher Nightmare Eclipse publicly disclosed LegacyHive after the July 2026 Patch Tuesday updates.

The exploit requires additional account credentials, which adds another barrier to exploitation. Cybersecurity researcher Kevin Beaumont later confirmed that the proof-of-concept worked and published Microsoft Defender for Endpoint detection queries that organizations could use to identify related activity.

Before Microsoft’s official update arrived, ACROS Security released free unofficial LegacyHive micropatches on July 20.

Users and administrators should install the August 2026 Windows security updates to receive Microsoft’s official protection against CVE-2026-62832.

LegacyHive may now be fixed, but Windows privilege escalation research continues. The researcher behind the disclosure has also released a separate exploit called ShieldBreak, which can reportedly grant SYSTEM-level access on fully patched Windows systems.

More about the topics: microsoft, security, Windows 11

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages