Security researcher NightmareEclipse/Chaotic Eclipse publicly released a proof-of-concept exploit for a Windows local elevation-of-privilege zero-day dubbed LegacyHive, targeting the Windows User Profile Service (ProfSvc). The flaw abuses arbitrary registry hive loading to let a standard user mount another user’s registry hive—particularly usrclass.dat—under their own registry classes root, potentially exposing sensitive registry data and enabling privileged read-write access that could support further escalation. Reports said the public PoC was intentionally limited and may require additional user credentials, while the researcher claimed the original technique could load arbitrary hives without that restriction.
The disclosure said the issue affects fully patched supported Windows desktop and server versions, including systems updated through July 2026, and no CVE, Microsoft advisory, or official patch had been identified at the time of publication. Researchers and defenders warned that, although the released PoC does not by itself guarantee full system compromise, it provides a strong post-compromise primitive that skilled attackers could weaponize quickly, especially given prior rapid criminal adoption of the researcher’s earlier Microsoft disclosures. Background documentation on Windows registry hives shows that user profile hives store application settings, desktop configuration, environment data, network connections, and other per-user information, underscoring the sensitivity of unauthorized hive access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
0patch announced free micropatches for the LegacyHive Windows User Profile Service elevation-of-privilege zero-day. This introduced a new third-party mitigation while Microsoft was still investigating the issue.
Microsoft said it is investigating the reported LegacyHive/User Profile Service local privilege-escalation vulnerability. At the time of the statement, no CVE or dedicated security bulletin had been assigned, despite claims that fully patched supported Windows systems were affected.
Kevin Beaumont published Microsoft Defender for Endpoint detection queries to help identify LegacyHive exploitation activity. The queries were released after public disclosure of the LegacyHive Windows privilege-escalation PoC.
Security researcher NightmareEclipse/Chaotic Eclipse publicly released a proof-of-concept exploit named LegacyHive for a Windows User Profile Service local elevation-of-privilege issue involving arbitrary registry hive loading. The disclosure said the public PoC was intentionally limited, while a more capable version could load arbitrary hives and reportedly worked on supported Windows systems even after July 2026 updates.
A GitHub repository for the LegacyHive proof-of-concept was published, describing a Windows User Profile Service local privilege-escalation issue involving arbitrary registry hive loading. The repository said the public PoC was intentionally limited, while claiming a more capable version affected supported Windows desktop and server systems even after July 2026 patching.
Microsoft published documentation describing Windows Registry hive structure, backing files, and how user profile hives are loaded and stored in Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
0patch.com
Open sourcelevelblue.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcegit.projectnightcrawler.dev
Open sourceblog.projectnightcrawler.dev
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.