Nightmare Eclipse publishes LegacyHive Windows zero-day
Nightmare Eclipse released LegacyHive, a local privilege‑escalation zero‑day in the Windows User Profile Service that can load other users’ registry hives, including administrators, with a PoC on July 2026 Patch Tuesday.
Nightmare Eclipse published LegacyHive on July 2026 Patch Tuesday. The exploit targets the Windows User Profile Service and can load another user’s registry hive under the current user’s classes root. The author also refers to the exploit as Chaotic Eclipse and released a partially stripped proof‑of‑concept that runs on systems with Microsoft’s July 2026 updates.
LegacyHive affects the component that loads and manages per‑user registry hives. Registry hives store configuration and user‑specific data used by Windows and applications. The exploit’s PoC mounts a target user’s hive into the current user’s classes root, a location that contains class registrations and per‑user settings stored in the usrclass.dat file.
The published PoC requires credentials for a second standard user account and a third username, which can be an administrator account. In a written note accompanying the release, the researcher said an earlier variant of the exploit did not require credentials and could load arbitrary hives, but that version was less reliable and would require additional work to make dependable.
The author released the proof‑of‑concept with parts removed to limit the chance of widespread abuse. The researcher has previously published multiple Windows zero‑days, including exploits referenced as BlueHammer, RedSun and UnDefend, along with GreenPlasma, RoguePlanet, YellowKey and GreatXML; some of those earlier disclosures were reported as used in attacks.
Microsoft had not publicly acknowledged LegacyHive or issued a patch for the vulnerability at the time of the exploit’s release. The researcher noted the PoC runs on machines with the July 2026 patches. Security teams and administrators assessing exposed systems can review account access and credential exposure, as the published code requires some level of local access to succeed.
The release provides code that reproduces the loading behavior against updated systems and the author indicated additional development could expand the exploit’s capabilities. No vendor fix had been published at the time of the release.








