Windows 0-day drops the same day Microsoft releases record number of patches

by | Jul 29, 2026 | Technology

Windows 0-day drops the same day Microsoft releases record number of patches

A zero-day vulnerability in Windows has been disclosed publicly on the same day Microsoft released a record volume of security patches. The exploit, named HiveLegacy, was published by a pseudonymous researcher known as NightmareEclypse, who has now released nine such exploits to date.

The vulnerability exists in the Windows User Profile Service and functions as an elevation-of-privilege attack. It allows users with limited system permissions to modify the registry settings associated with administrator accounts, specifically targeting the classes registry hive that determines which applications open when certain file types are accessed. The exploit requires the attacker to possess credentials for at least one user account and knowledge of an administrator username, though the attacking account does not need to have administrative privileges itself.

Security researchers have confirmed the exploit functions as described. According to vulnerability analyst Will Dormann, the ability to modify an administrator’s registry hive represents a significant security primitive that could enable attackers to execute code with administrative privileges when the admin user logs in. Experts suggest the vulnerability could potentially be combined with other exploits to achieve full administrative access without requiring additional user interaction or knowledge.

Microsoft stated it is investigating the vulnerability report and reiterated its preference that security researchers follow coordinated disclosure practices. For immediate protection, Windows users can deploy a detection script created by independent researcher Kevin Beaumont. Additional defensive measures include restricting local user account creation, monitoring the Profile Service for unexpected registry hive operations, and tracking activity related to user profile files.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI