Windows 0-day drops the same day Microsoft releases record number of patches

by | Aug 8, 2026 | Technology

Windows 0-day drops the same day Microsoft releases record number of patches

A zero-day vulnerability in Windows was publicly disclosed on the same day Microsoft released a historically large number of security patches. The flaw, identified as HiveLegacy by security researchers, exploits a weakness in the Windows User Profile Service to enable privilege escalation attacks.

The vulnerability allows users with limited system permissions to modify the registry settings of administrator accounts, specifically targeting the classes registry hive that determines which applications open certain file types in Windows Explorer. To execute the attack, an attacker must possess credentials for a non-administrative user account and know the username of another user on the target system. Security analysts have characterized the vulnerability as a significant primitive that could be leveraged for more sophisticated attacks, potentially allowing attackers to execute code with administrative privileges when targeted admin users log in.

The exploit code was published by an anonymous researcher using the handle NightmareEclypse, who has released nine similar exploits to date. The researcher stated that the proof-of-concept code was intentionally stripped of certain capabilities to minimize the risk of malicious exploitation. Security experts including Will Dormann of Tharros Labs noted that the ability to modify an administrator’s registry hive represents a powerful capability that skilled attackers could readily extend to accomplish additional objectives.

Microsoft acknowledged awareness of the vulnerability and initiated an investigation. The company reiterated its preference for coordinated vulnerability disclosure practices. In the interim, Windows users can implement protective measures including running detection scripts, restricting local non-user account creation, monitoring the ProfSvc process for unexpected hive loads, and tracking activity related to NTUSER.DAT and UsrClass.dat files.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI