LegacyHive Windows Zero-Day Has No Official Fix, but a Micropatch Is Available
The LegacyHive Windows zero-day allows a local non-admin user to access another user’s registry hive and potentially gain elevated privileges. Microsoft is investigating the vulnerability, but no official security update is available.
LegacyHive Affects the Windows User Profile Service
The newly disclosed flaw affects the Windows User Profile Service and can expose fully updated Windows systems to local privilege escalation attacks. Microsoft has not assigned the vulnerability a CVE ID.
An attacker must already have access to a non-administrator account on the targeted computer, and the flaw could then help that attacker access sensitive registry data or prepare the system for code execution with higher privileges.
How the LegacyHive Exploit Works
LegacyHive allows a standard Windows user to mount another user’s registry hive with full access.
With this access, an attacker could extract secrets stored in the registry, read information belonging to another user, modify protected registry values, and add entries that execute code when an administrator signs in.
The final stage of the attack can occur when an administrator logs into the compromised computer, at which point Windows may process the modified registry entries and run the attacker’s code with elevated permissions.
Microsoft Is Investigating the Vulnerability
Microsoft confirmed that it is investigating the reported LegacyHive vulnerability. The company has not released an official security update or workaround and says it will update affected products after completing its investigation.
This means supported and fully updated Windows installations may remain vulnerable until Microsoft releases a fix.
0patch Releases a Free LegacyHive Fix
ACROS Security has released free unofficial micropatches for LegacyHive through its 0patch service.
The micropatch blocks the attacker from accessing the targeted administrator registry hive by redirecting the exploit to a temporary user profile hive instead, preventing the attack from reaching sensitive administrator data.
Users can apply the micropatch without restarting Windows, and it offers temporary protection while Microsoft investigates and prepares an official update.
Which Windows Versions Are Affected?
LegacyHive affects Windows 10 version 2004 and later releases, as well as newer versions of Windows Server.
Systems released before Windows 10 version 2004 and Windows Server 2019 are not affected by the flaw. Affected devices include supported Windows versions that have received the latest available security updates.
Other Nightmare Eclipse Vulnerabilities Remain Unpatched
The researcher behind LegacyHive has disclosed several other Windows security vulnerabilities under the Nightmare Eclipse project.
One of those flaws, called RoguePlanet, received a fix in Microsoft’s July 2026 security updates. Several other reported Nightmare Eclipse vulnerabilities remain unpatched, and Microsoft has not provided release dates for fixes addressing those issues.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages