Microsoft has patched CVE-2026-62832, a high-severity Windows User Profile Service elevation-of-privilege flaw publicly known as LegacyHive. The vulnerability stems from improper link resolution before file access (CWE-59) and affects supported versions of Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025 prior to patched builds. Microsoft scored the bug 7.8 CVSS v3.1, and the issue allows an authorized local attacker to escalate privileges on vulnerable systems.
Public reporting said the flaw could let an authenticated attacker with credentials for another local account load that user's registry hive, alter data, and potentially obtain administrator privileges without user interaction. The zero-day was publicly disclosed by the researcher known as Nightmare Eclipse, who released a proof-of-concept exploit after the July Patch Tuesday updates; researchers including Will Dormann and Kevin Beaumont analyzed the exploit, while ACROS Security had already issued unofficial 0Patch micropatches before Microsoft's official advisory and fix were released.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-62832 was published, describing a Windows User Profile Service elevation-of-privilege flaw caused by improper link resolution before file access. The record says an authorized local attacker can elevate privileges and assigns a CVSS 7.8 High severity rating.
Microsoft released an official fix for LegacyHive in its August 2026 Patch Tuesday updates, tracking the issue as CVE-2026-62832. The patch addressed the Windows User Profile Service zero-day that could let a local authenticated attacker gain administrator privileges without user interaction.
ACROS Security released free unofficial micropatches for LegacyHive through its 0Patch platform, covering Windows 10 version 2004 or later and Windows Server 2022 or later. This provided a third-party mitigation before Microsoft's official fix.
One day after the proof-of-concept was released, Kevin Beaumont published Microsoft Defender for Endpoint detection queries for LegacyHive and confirmed the exploit worked. This added independent validation and defensive guidance for the vulnerability.
Hours after the July 2026 Patch Tuesday updates were released, Nightmare Eclipse published a proof-of-concept exploit for LegacyHive. Researchers later said the exploit could let a non-admin modify another user's registry hive and potentially gain code execution when an administrator logs in.
A researcher using the handle Nightmare Eclipse publicly disclosed the Windows User Profile Service vulnerability later tracked as CVE-2026-62832. Microsoft said it was aware of the report and was investigating the validity and applicability of the claims.
The CVE entry for CVE-2026-62832 was updated after publication. The record continued to reference Microsoft's advisory and affected Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025 builds prior to patched versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecve.org
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.