Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft patched a Windows zero-day vulnerability called LegacyHive in the August 2026 Patch Tuesday updates. The flaw allows a local attacker with credentials for another user account to load that user's registry hive and gain administrator privileges without user interaction. The vulnerability stems from improper link resolution in the Windows User Profile Service. Proof-of-concept exploit code was publicly released shortly after the July 2026 Patch Tuesday, but it requires additional credentials, limiting ease of exploitation. Microsoft tracks this issue as CVE-2026-62832 and has released official patches. Unofficial patches were also made available prior to the official fix.
AI Analysis
Technical Summary
LegacyHive is a local privilege escalation vulnerability in the Windows User Profile Service caused by improper link resolution before file access ('link following'). An authenticated attacker with credentials for a local account can run a specially crafted application to load another user's registry hive, resulting in automatic code execution with administrator privileges when the targeted admin logs in. The vulnerability was disclosed after the July 2026 Patch Tuesday, with proof-of-concept exploit code released by the researcher 'Nightmare Eclipse'. Microsoft released official patches in the August 2026 Patch Tuesday updates and tracks the vulnerability as CVE-2026-62832. The exploit requires valid credentials, making it harder to weaponize compared to other zero-days. ACROS Security released unofficial patches for Windows 10 2004+ and Windows Server 2022+ prior to Microsoft's official update.
Potential Impact
Successful exploitation allows a local attacker with credentials for a non-administrator account to gain administrator privileges by loading another user's registry hive and executing code automatically upon admin login. This elevates the attacker's privileges on the system without requiring user interaction. The vulnerability affects the Windows User Profile Service and could lead to unauthorized access or modification of another user's data and system control.
Mitigation Recommendations
Microsoft has released official patches for this vulnerability as part of the August 2026 Patch Tuesday updates. Systems should be updated promptly to apply these fixes. Prior to the official patch, ACROS Security provided unofficial patches for Windows 10 version 2004 and later, and Windows Server 2022 and later. No additional mitigation steps are indicated by Microsoft beyond applying the official update.
Microsoft patches LegacyHive Windows zero-day vulnerability
Description
Microsoft patched a Windows zero-day vulnerability called LegacyHive in the August 2026 Patch Tuesday updates. The flaw allows a local attacker with credentials for another user account to load that user's registry hive and gain administrator privileges without user interaction. The vulnerability stems from improper link resolution in the Windows User Profile Service. Proof-of-concept exploit code was publicly released shortly after the July 2026 Patch Tuesday, but it requires additional credentials, limiting ease of exploitation. Microsoft tracks this issue as CVE-2026-62832 and has released official patches. Unofficial patches were also made available prior to the official fix.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LegacyHive is a local privilege escalation vulnerability in the Windows User Profile Service caused by improper link resolution before file access ('link following'). An authenticated attacker with credentials for a local account can run a specially crafted application to load another user's registry hive, resulting in automatic code execution with administrator privileges when the targeted admin logs in. The vulnerability was disclosed after the July 2026 Patch Tuesday, with proof-of-concept exploit code released by the researcher 'Nightmare Eclipse'. Microsoft released official patches in the August 2026 Patch Tuesday updates and tracks the vulnerability as CVE-2026-62832. The exploit requires valid credentials, making it harder to weaponize compared to other zero-days. ACROS Security released unofficial patches for Windows 10 2004+ and Windows Server 2022+ prior to Microsoft's official update.
Potential Impact
Successful exploitation allows a local attacker with credentials for a non-administrator account to gain administrator privileges by loading another user's registry hive and executing code automatically upon admin login. This elevates the attacker's privileges on the system without requiring user interaction. The vulnerability affects the Windows User Profile Service and could lead to unauthorized access or modification of another user's data and system control.
Mitigation Recommendations
Microsoft has released official patches for this vulnerability as part of the August 2026 Patch Tuesday updates. Systems should be updated promptly to apply these fixes. Prior to the official patch, ACROS Security provided unofficial patches for Windows 10 version 2004 and later, and Windows Server 2022 and later. No additional mitigation steps are indicated by Microsoft beyond applying the official update.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a7e08c5bf8831d5399b6d6d
Added to database: 08/13/2026, 18:11:17 UTC
Last enriched: 08/13/2026, 18:11:28 UTC
Last updated: 08/14/2026, 00:08:49 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.