Windows 0-day drops the same day Microsoft releases record number of patches

by | Aug 1, 2026 | Technology

Windows 0-day drops the same day Microsoft releases record number of patches

A security researcher operating under the pseudonym NightmareEclypse has disclosed exploit code targeting a zero-day vulnerability in Windows, marking the ninth such publication by this researcher. The flaw, termed HiveLegacy, affects the Windows User Profile Service and permits users with limited system privileges to elevate their access by modifying an administrator account’s classes registry hive—a component that determines which application opens specific file types in Windows Explorer.

According to security analysts, the vulnerability represents a significant security concern. The exploit requires the attacker to possess credentials for at least one non-administrator account and knowledge of a third account’s username. By manipulating the registry hive of an administrator’s account, an attacker can potentially execute code with elevated privileges when the compromised administrator logs in. Researchers have characterized this capability as a “powerful primitive” that could be leveraged for additional malicious purposes beyond the basic proof-of-concept demonstration.

Will Dormann, a vulnerability analyst, explained that the flaw’s real danger lies in its potential for chaining with other exploits to gain direct administrative access. The vulnerability operates by exploiting how Windows loads user class hives during login—a process that occurs under SYSTEM context before user authentication completes, creating an attack surface that HiveLegacy abuses.

Microsoft acknowledged awareness of the vulnerability and stated it is investigating the matter. The company reiterated its preference for researchers to adhere to coordinated disclosure practices. Meanwhile, defenders can employ countermeasures including a detection script developed by independent researcher Kevin Beaumont, restricting local account creation, monitoring the ProfSvc process for unexpected hive loads, and tracking activity related to user profile files.

The disclosure coincided with Microsoft releasing a record volume of security patches earlier in the week, underscoring the ongoing challenge of managing vulnerabilities in widely-deployed software platforms.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI