bleeping-computer · Crawled Jul 17, 2026

New Windows LegacyHive zero-day gives hackers admin privileges

1 IoCs
Read original article ↗

AI Summary

A security researcher known as Nightmare Eclipse has released a Windows zero-day exploit named LegacyHive, which enables privilege escalation on fully patched systems by exploiting a flaw in the Windows User Profile Service. The proof-of-concept requires additional user credentials to limit weaponization, but successful exploitation allows non-admin users to manipulate registry hives and achieve automatic code execution upon administrator login. Microsoft has not yet assigned a CVE to this vulnerability, and the company has issued warnings against malicious use of such disclosures.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub User Nightmare Eclipse Details →