A safety researcher utilizing the deal with “Nightmare Eclipse” has launched a Home windows zero-day exploit referred to as LegacyHive that enables attackers to escalate privileges on trendy Home windows methods.
Nightmare Eclipse revealed a proof-of-concept (PoC) exploit hours after Microsoft launched its July 2026 Patch Tuesday replace, saying it exploits a safety vulnerability within the Home windows Consumer Profile Service, which has not but acquired a CVE ID to make it simpler to trace.
Nonetheless, in contrast to earlier exploits launched by NightmwareEclipse, the LegacyHive PoC has been modified to require extra credentials, making it troublesome for attackers to take advantage of this vulnerability.
“A PoC requires one other normal person credential and a 3rd username (probably an administrator account), and a profitable PoC will finally end result within the goal person hive being mounted on the root of the present person class,” the researcher mentioned.
“The PoC was eliminated in an try to stop public exploitation. The unique PoC didn’t require any extra person credentials and was not restricted to the usrclass.dat hive. This vulnerability might be used to load any hive, however it could require mind cells to drive the PoC to take action.”
As Tharros Principal Vulnerability Analyst Will Dormann defined after testing the LegacyHive exploit, a profitable exploit may permit a non-administrator to change the category registry hive, permitting code to run routinely when an administrator account is logged right into a compromised system.
“For instance, what’s new is which you can affiliate the .txt file you open with calc.exe,” Dormann mentioned. “A sensible attacker or somebody who desires to perform one thing can simply determine the way to do one thing extra fascinating or that does not require person interplay.
A day after the PoC was revealed, cybersecurity knowledgeable Kevin Beaumont additionally confirmed that the exploit labored and revealed LegacyHive exploit detection queries for the Microsoft Defender for Endpoint (MDE) enterprise-grade endpoint safety platform.
In current months, Nightmare Eclipse has revealed zero-day exploits for a number of vulnerabilities in Home windows. in Varied Home windows parts together with Microsoft Defender, BitLocker, and RoguePlanet BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend.
Final month, Microsoft fastened the GreenPlasma, MiniPlasma, and YellowKey flaws as a part of its June 2026 Patch Tuesday replace, and glued the RoguePlanet vulnerability in its July safety replace.
Microsoft responded to the Nightmare Eclipse revelations by warning of authorized motion in opposition to individuals participating in “malicious actions that trigger actual hurt to our clients,” main cybersecurity specialists to marvel if the corporate was instantly threatening safety researchers.
BleepingComputer reached out to a Microsoft spokesperson for remark, however didn’t obtain a response.

Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remaining strikes invisibly by the surroundings.
Picus’ whitepaper reveals the way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
