Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure

TL;DR Summary
Microsoft issued August Patch Tuesday updates to fix CVE-2026-62832, a Windows User Profile Service zero-day nicknamed LegacyHive that could let an authenticated local attacker load another user's registry hive and gain administrator privileges. The Nightmare Eclipse PoC reportedly required credentials, limiting weaponization, and defenders published Defender detection queries while 0Patch released unofficial patches; several related zero-days remain unpatched.
- Microsoft patches LegacyHive Windows zero-day vulnerability BleepingComputer
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack The Hacker News
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack Check Point Research
- Patch Tuesday: Update now to fix 421 flaws, including three zero-days Malwarebytes
- Microsoft Plugs Nearly 400 Security Holes krebsonsecurity.com
Reading Insights
Total Reads
0
Unique Readers
8
Time Saved
3 min
vs 4 min read
Condensed
92%
699 → 58 words
Want the full story? Read the original article
Read on BleepingComputer