A Windows 0-day vulnerability called LegacyHive allows non-admin users to escalate privileges by abusing how Windows loads user class hives, with Microsoft investigating and detection scripts available.
<p>Right on the heels of Microsoft releasing a <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/">record number</a> of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts.</p>
<p>The exploit, which multiple researchers <a href="https://infosec.exchange/@wdormann/116925149776495861">say</a> <a href="https://infosec.exchange/@[email protected]/116924831427611458">works</a>, is sending Microsoft scrambling, yet again, to patch a zero-day released by an anonymous researcher who has complained about the software maker’s handling of their bug reports. To date, the pseudonymous NightmareEclypse has published nine such exploits, including <a href="https://blog.projectnightcrawler.dev/posts/2026-07-14-legacyhive-public-disclosure/">Tuesday’s HiveLegacy</a>. The researcher said the proof-of-concept code included in the report was stripped down to prevent attackers from using it maliciously.</p>
<h2>A “pretty powerful primitive”</h2>
<p>HiveLegacy is an elevation-of-privilege exploit that targets a vulnerability residing in the Windows User Profile Service. It allows users (and with more work likely processes) with limited system rights to compromise an admin user's account by modifying its <a href="https://learn.microsoft.com/en-us/troubleshoot/windows-server/performance/windows-registry-advanced-users">classes registry hive</a>, a resource that ensures the correct application opens when certain types of files are clicked on in Windows Explorer.</p><p><a href="https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches/#comments">Comments</a></p>
# Windows 0-day drops the same day Microsoft releases record number of patches
Source: [https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches/](https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches/)
“If I can set up the system so that it runs my code when the admin user logs in,” the attacker has de facto administrator privileges, Will Dormann, a senior principal vulnerability analyst at Tharros Labs, said in an interview\. “I don’t need to be an admin myself\.”
In a[post](https://infosec.exchange/@wdormann/116925161094454791), he said that “the ability of a non\-admin user to be able to modify the classes registry hive of an admin user is a pretty powerful primitive\. Clever attackers or people who want to accomplish something will easily be able to figure out how to do things that are more interesting and/or don’t even require user interaction\.”
Dormann said that the exploit could possibly be chained to a separate one that gives direct access to an administrative account\.
As explained in a[post](https://infosec.exchange/@kallisti/116924591783535421)by a different analyst: “When a new user is logging on, Windows needs to load the user’s class hive\. Since the user isn’t logged on before logging on \(tautology, I know\), it can’t be loaded in the context of the user\. So it is loaded in the context of NT AUTHORITY\\SYSTEM\. LegacyHive abuses this\.”
In an emailed statement, Microsoft said it’s aware of the vulnerability report and is investigating\. The company also noted its preference that vulnerability reporters follow a[coordinated disclosure](https://www.microsoft.com/en-us/msrc/cvd)policy\.
For now, Windows users who want to protect their systems against HiveLegacy can run a[detection script](https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql)published by independent researcher Kevin Beaumont\. Other defenses are to restrict local non\-user account creation, monitor ProfSvc for unexpected hive loads, and track NTUSER\.DAT/UsrClass\.dat activity\.
An anonymous researcher released two Microsoft zero-day exploits, YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation), after Patch Tuesday, posing serious security risks for organizations.
Microsoft patched a zero-day vulnerability in Windows Defender (CVE-2026-50656) but the patch may cause disk space exhaustion due to a new bug that allows writing unlimited file sizes.
Microsoft fixed a 0-day vulnerability disclosed by researcher Nightmare Eclipse amid a heated rivalry, alongside other vulnerabilities like MiniPlasma, YellowKey, and others. The researcher published exploit code for a new Windows Defender vulnerability.
Microsoft released patches for nearly 400 security vulnerabilities, including one actively exploited zero-day, as AI-driven discovery continues to swell patch volumes.
Microsoft issued over 974 security patches, including critical zero-day vulnerabilities, marking its largest single patch batch to date, with AI aiding in faster vulnerability discovery.