PoC public Windows User Profile Service zero-day Microsoft privilege-escalation
Microsoft patches LegacyHive Windows zero-day vulnerability
CVE Tools coverage
Microsoft has addressed a zero-day vulnerability in the Windows User Profile Service, tracked as CVE-2026-62832, through its August Patch Tuesday updates. The flaw, dubbed "LegacyHive" by researcher Nightmare Eclipse, involves improper link resolution that permits local attackers to escalate privileges to administrator level. Although a proof-of-concept exploit was made public shortly after the July security release, it requires specific local credentials for successful exploitation.
Analysts have confirmed that the exploit can modify registry hives to grant automatic code execution upon admin login, and unofficial mitigations were previously provided by ACROS Security for recent Windows versions.