2 min read

Free 0Patch fix arrives for Windows LegacyHive zero-day

An unofficial free patch is available for the LegacyHive Windows zero-day, which can let non-admin users gain code execution when an admin logs in.

Image: BleepingComputer

A newly disclosed Windows zero-day known as LegacyHive already has a free unofficial fix, even though Microsoft has not yet assigned it a CVE ID or shipped a security update.

The flaw was discovered by security researcher Nightmare Eclipse in the Windows User Profile Service and disclosed on the same day Microsoft released its July 2026 Patch Tuesday updates. The researcher also published a stripped-down proof-of-concept exploit intended to make weaponization harder.

After reviewing the PoC, Will Dormann, principal vulnerability analyst at Tharros, said a non-admin user could exploit LegacyHive to modify the classes registry hive and gain automatic code execution when an administrator logs into the compromised machine. Kevin Beaumont separately confirmed the exploit worked a day after the PoC was released and shared Microsoft Defender for Endpoint detection queries.

Microsoft told BleepingComputer it is investigating.

Recommended reading

WordPress bugs trigger active attacks and full site takeovers

“Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims.” “Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible.”

Microsoft spokesperson

ACROS Security, the company behind 0Patch, has now released free unofficial micropatches. CEO Mitja Kolsek said the bug lets a regular user mount another user’s registry hive with full access, allowing them to extract stored secrets or change registry values to affect what runs at the next login.

According to Kolsek, systems with 0Patch enabled still allow the exploit path to run, but it loads a temporary user profile hive instead of the administrator’s hive, making the attack ineffective.

The issue affects Windows 10 2004 or later and Windows Server 2022 or later. ACROS said older versions than Windows 10 2004 and Windows Server 2019 are not affected. To install the patch, users need to register a 0Patch account and install the 0Patch agent. If no custom policies block it, the micropatch deploys automatically and does not require a restart.

Nightmare Eclipse has disclosed multiple Microsoft zero-days in recent months, including RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. Microsoft fixed YellowKey, GreenPlasma, and MiniPlasma in the June 2026 Patch Tuesday updates, and RoguePlanet in the July updates. The others remain unpatched.

Whitepaper ad
Whitepaper ad
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

// Keep reading