Microsoft Finally Patches LegacyHive Windows Zero-Day
Microsoft has patched the LegacyHive Windows vulnerability through the August 2026 Patch Tuesday updates, as BleepingComputer writes. The flaw could allow a local attacker to gain administrator privileges without user interaction.
Tracked as CVE-2026-62832, the vulnerability affects the Windows User Profile Service. Microsoft fixed it alongside around 400 other security flaws addressed this month.
LegacyHive could let attackers access another user’s registry hive
LegacyHive stems from improper link resolution before file access in the Windows User Profile Service.
An attacker needs credentials for another local account before attempting exploitation. A specially crafted application can then load that user’s registry hive, allowing the attacker to read or modify data that should remain inaccessible.
Researcher Will Dormann demonstrated how an attacker could modify the classes hive and trigger code execution when an administrator signs in. Successful exploitation could ultimately elevate privileges to administrator level.
Researchers published a working proof-of-concept
Security researcher Nightmare Eclipse publicly disclosed LegacyHive after the July 2026 Patch Tuesday updates.
The exploit requires additional account credentials, which adds another barrier to exploitation. Cybersecurity researcher Kevin Beaumont later confirmed that the proof-of-concept worked and published Microsoft Defender for Endpoint detection queries that organizations could use to identify related activity.
Before Microsoft’s official update arrived, ACROS Security released free unofficial LegacyHive micropatches on July 20.
Users and administrators should install the August 2026 Windows security updates to receive Microsoft’s official protection against CVE-2026-62832.
LegacyHive may now be fixed, but Windows privilege escalation research continues. The researcher behind the disclosure has also released a separate exploit called ShieldBreak, which can reportedly grant SYSTEM-level access on fully patched Windows systems.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages