All stories

Local users can load administrative hives via Windows User Profile Service zero-day

A new zero-day vulnerability in the Windows User Profile Service allows local users to load administrative user hives. The exploit, dubbed LegacyHive, was released by researcher Nightmare Eclipse alongside a proof-of-concept that works on systems even after July 2026 patches. Defenders should monitor for unusual hive mounting activity within the current user classes root.

Summary

A security researcher has disclosed an unpatched local privilege escalation vulnerability in the Windows User Profile Service. The flaw, named LegacyHive, enables an attacker to mount the registry hives of other users-including administrators-into their own session.

The disclosure comes from Nightmare Eclipse (also known as Chaotic Eclipse), a researcher who has previously released several zero-day exploits targeting Microsoft products. While the current proof-of-concept is stripped of certain capabilities to hinder immediate widespread exploitation, the underlying vulnerability remains unpatched by Microsoft.

Technical details

LegacyHive targets the Windows User Profile Service to achieve privilege escalation. When successfully exploited, the vulnerability allows a user to mount a target user's hive into the current user classes root.

The current version of the exploit requires three specific components:

  • The credentials of a standard user account.
  • A third username, which can be an administrator account.

According to the researcher, the original version of this vulnerability was more potent; it did not require additional user credentials and was not limited to loading the usrclass.dat hive. While the current proof-of-concept is restricted, the researcher notes that loading any arbitrary hive remains possible with further development.

Proof of Concept

A functional proof-of-concept has been released by the researcher. This PoC is reportedly effective on all currently supported desktop and server installations, including those running Microsoft's July 2026 patches.

A working proof-of-concept is published at https://github.com/MSNightmare/LegacyHive

Why this matters for defenders

This vulnerability presents a significant risk because it allows a standard user to gain access to the registry data of higher-privileged accounts. Because the exploit works on systems that have already applied the July 2026 updates, traditional patching cycles will not mitigate this specific flaw until a new security update is issued.

The researcher's history includes several other zero-days targeting Microsoft, such as BlueHammer, RedSun, UnDefend, GreenPlasma, RoguePlanet, YellowKey, and GreatXML. This latest release follows a pattern of disclosing unpatched defects in core Windows services.

What remains unclear

Microsoft has not yet acknowledged the LegacyHive exploit or provided a timeline for a fix. It is currently unknown if the vulnerability can be mitigated through registry changes or group policy objects without a formal security update from the vendor. Additionally, while the current PoC is "stripped," the full potential of the exploit-specifically its ability to load any hive without credentials-has not been publicly demonstrated in its original form.

Sources

  1. https://www.securityweek.com/nightmare-eclipse-drops-legacyhive-windows-zero-day/
  2. https://github.com/MSNightmare/LegacyHive
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -