news.mlab.sh
Back to the feed
vulnerability

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

High
Summary

Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requires user credentials to load other users’ hives, including those of administrators. Microsoft has not yet commented on the vulnerability, but this follows a series of previous zero-day releases by the researcher.

Nightmare Eclipse, a security researcher known for releasing unpatched zero-day exploits targeting Microsoft products, has dropped another vulnerability this week. The new exploit, named LegacyHive, is a local privilege escalation bug within the Windows User Profile Service. This allows an attacker to load other users’ hives, including those of administrators, without needing to know the target user’s password.

Nightmare Eclipse provided a proof-of-concept (PoC) exploit code that functions on systems running Microsoft’s July 2026 patches. The researcher notes that the original version of the exploit did not require user credentials and could load any hive, not just the usrclass.dat hive. However, this functionality remains possible with some additional work.

To date, Nightmare Eclipse has released over half a dozen zero-days in Microsoft products, including BlueHammer, RedSun, and UnDefend, which have been exploited in attacks, alongside GreenPlasma, RoguePlanet, YellowKey, and GreatXML. Microsoft has not yet acknowledged the LegacyHive exploit. SecurityWeek has reached out to Microsoft for a statement and will update this article if a response is received.

This vulnerability highlights the ongoing risk posed by disgruntled researchers releasing zero-day exploits. The fact that this exploit requires user credentials demonstrates a level of sophistication, even if it’s not immediately straightforward to exploit.

Read the full article at SecurityWeek