Security researcher NightmareEclipse/Chaotic Eclipse publicly released a proof-of-concept exploit for a Windows local elevation-of-privilege zero-day dubbed LegacyHive, targeting the Windows User Profile Service (ProfSvc). The flaw abuses arbitrary registry hive loading to let a standard user mount another user’s registry hive—particularly usrclass.dat—under their own registry classes root, potentially exposing sensitive registry data and enabling privileged read-write access that could support further escalation. Reports said the public PoC was intentionally limited and may require additional user credentials, while the researcher claimed the original technique could load arbitrary hives without that restriction.
The disclosure said the issue affects fully patched supported Windows desktop and server versions, including systems updated through July 2026, and no CVE, Microsoft advisory, or official patch had been identified at the time of publication. Researchers and defenders warned that, although the released PoC does not by itself guarantee full system compromise, it provides a strong post-compromise primitive that skilled attackers could weaponize quickly, especially given prior rapid criminal adoption of the researcher’s earlier Microsoft disclosures. Background documentation on Windows registry hives shows that user profile hives store application settings, desktop configuration, environment data, network connections, and other per-user information, underscoring the sensitivity of unauthorized hive access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
LevelBlue’s OpsIntel CTI and THOR teams independently reproduced the LegacyHive proof of concept and published a detailed attack chain showing how Windows profile initialization, registry hive loading, oplocks, and NT Object Manager path redirection can be abused for local privilege escalation on fully patched systems. The write-up also characterized LegacyHive as primarily a post-compromise technique because the public PoC requires helper-account credentials and recommended behavioral detections tied to anomalous profile and hive activity.
0patch announced free micropatches for the LegacyHive Windows User Profile Service elevation-of-privilege zero-day. This introduced a new third-party mitigation while Microsoft was still investigating the issue.
Microsoft said it is investigating the reported LegacyHive/User Profile Service local privilege-escalation vulnerability. At the time of the statement, no CVE or dedicated security bulletin had been assigned, despite claims that fully patched supported Windows systems were affected.
Kevin Beaumont published Microsoft Defender for Endpoint detection queries to help identify LegacyHive exploitation activity. The queries were released after public disclosure of the LegacyHive Windows privilege-escalation PoC.
Security researcher NightmareEclipse/Chaotic Eclipse publicly released a proof-of-concept exploit named LegacyHive for a Windows User Profile Service local elevation-of-privilege issue involving arbitrary registry hive loading. The disclosure said the public PoC was intentionally limited, while a more capable version could load arbitrary hives and reportedly worked on supported Windows systems even after July 2026 updates.
A GitHub repository for the LegacyHive proof-of-concept was published, describing a Windows User Profile Service local privilege-escalation issue involving arbitrary registry hive loading. The repository said the public PoC was intentionally limited, while claiming a more capable version affected supported Windows desktop and server systems even after July 2026 patching.
Microsoft published documentation describing Windows Registry hive structure, backing files, and how user profile hives are loaded and stored in Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open source0patch.com
Open sourcelevelblue.com
Open sourcegithub.com
Open sourcegit.projectnightcrawler.dev
Open sourcegithub.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.