Microsoft Patches LegacyHive Windows User Profile Logic Vulnerability
Microsoft has patched LegacyHive, a logic-based local privilege escalation (LPE) primitive targeting the Windows User Profile Service (ProfSvc). The vulnerability allows a low-privileged attacker to redirect the loading of a target user's UsrClass.dat registry hive into their own namespace via Object Manager symbolic link redirection and synchronized profile loading. This primitive enables unauthorized cross-user access to sensitive registry data, including application configurations and Windows Explorer history. While initially disclosed as a zero-day by researcher NightmareEclipse and verified by Cyderes' Howler Cell, the flaw is now addressed in a recent massive security update cycle.
Microsoft Windows LegacyHive ProfSvc Zero-Day LPE
The LegacyHive vulnerability is a critical Local Privilege Escalation (LPE) flaw within the Windows User Profile Service (ProfSvc) affecting fully patched Windows desktop and server environments. Disclosed by researcher Nightmare Eclipse shortly after the July 2026 Patch Tuesday, the exploit enables attackers with local access to bypass security controls by unauthorizedly loading and unloading other users' registry hives. This mechanism allows for the extraction of sensitive application data and Windows Explorer history, providing a direct path to escalate privileges to the administrative level.