Microsoft patches LegacyHive Windows zero-day vulnerability
PoC publicWindows User Profile ServiceOur summary
Microsoft has addressed a zero-day vulnerability in the Windows User Profile Service, tracked as CVE-2026-62832, through its August Patch Tuesday updates. The flaw, dubbed "LegacyHive" by researcher Nightmare Eclipse, involves improper link resolution that permits local attackers to escalate privileges to administrator level. Although a proof-of-concept exploit was made public shortly after the July security release, it requires specific local credentials for successful exploitation.
Analysts have confirmed that the exploit can modify registry hives to grant automatic code execution upon admin login, and unofficial mitigations were previously provided by ACROS Security for recent Windows versions.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.