bleeping-computer · Crawled Aug 13, 2026

Microsoft patches LegacyHive Windows zero-day vulnerability

Read original article ↗

AI Summary

Microsoft has patched a Windows zero-day vulnerability known as 'LegacyHive' (CVE-2026-62832), which affects the Windows User Profile Service and allows authenticated local attackers to gain administrator privileges by exploiting improper link resolution during registry hive loading. The vulnerability was publicly disclosed and demonstrated by security researcher Nightmare Eclipse, who criticized Microsoft's disclosure practices. Exploitation does not require user interaction and enables privilege escalation by modifying another user's registry hive when they log in.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.