Windows 0-day drops the same day Microsoft releases record number of patches

by | Aug 5, 2026 | Technology

Windows 0-day drops the same day Microsoft releases record number of patches

A researcher operating under the pseudonym NightmareEclypse released exploit code for a previously unknown Windows vulnerability on Tuesday, the same day Microsoft deployed a record volume of security patches. The exploit, named HiveLegacy, enables users with limited system privileges to make unauthorized changes to administrator accounts, according to multiple independent researchers who verified its functionality.

The vulnerability exists in the Windows User Profile Service and allows attackers to modify the classes registry hive of a targeted administrator account. This registry hive controls which applications launch when specific file types are opened in Windows Explorer. To execute the attack, an attacker must possess credentials for one user account and knowledge of the target administrator’s username, though neither account necessarily requires administrative privileges. Security analysts indicate the exploit represents what they term a “powerful primitive,” suggesting it could serve as a foundation for more sophisticated attacks.

According to Will Dormann, a senior principal vulnerability analyst at Tharros Labs, the ability to modify an administrator’s registry settings effectively grants administrative access without requiring the attacker to hold admin status themselves. He noted that once configured to execute code upon admin login, the attacker gains de facto administrator privileges. Other security researchers have suggested the exploit could potentially be combined with additional vulnerabilities to achieve direct administrative access.

Microsoft confirmed it is investigating the vulnerability report and reiterated its preference that researchers follow coordinated disclosure practices when reporting security issues. The company has not yet released a patch. In the interim, Windows users can employ defensive measures including running a detection script developed by independent researcher Kevin Beaumont, restricting creation of non-user local accounts, monitoring the Profile Service for unexpected registry hive loads, and tracking activity related to NTUSER.DAT and UsrClass.dat files.

This marks the ninth exploit published by NightmareEclypse, who has previously criticized Microsoft’s handling of vulnerability reports. The researcher stated that the proof-of-concept code released with the report was intentionally stripped of certain functionality to prevent malicious misuse by threat actors.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI