Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure

1 min read
Source: BleepingComputer
Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure
Photo: BleepingComputer
TL;DR

Microsoft issued August Patch Tuesday updates to fix CVE-2026-62832, a Windows User Profile Service zero-day nicknamed LegacyHive that could let an authenticated local attacker load another user's registry hive and gain administrator privileges. The Nightmare Eclipse PoC reportedly required credentials, limiting weaponization, and defenders published Defender detection queries while 0Patch released unofficial patches; several related zero-days remain unpatched.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer