Windows 0-day drops the same day Microsoft releases record number of patches

by | Aug 11, 2026 | Technology

Windows 0-day drops the same day Microsoft releases record number of patches

A vulnerability researcher operating under the pseudonym NightmareEclypse has released proof-of-concept code for a Windows zero-day exploit designated HiveLegacy, which enables users with limited system privileges to modify sensitive registry settings associated with administrator accounts. The disclosure occurred on the same day Microsoft released a record number of security patches. Multiple researchers have confirmed the exploit’s functionality, prompting Microsoft to investigate the vulnerability.

The HiveLegacy exploit targets the Windows User Profile Service and functions as an elevation-of-privilege vulnerability. By manipulating the classes registry hive—a system resource that determines which application opens specific file types in Windows Explorer—attackers with low-privilege access can compromise administrator accounts. The attack requires the attacker to possess credentials for at least one user account on the target system, though that account need not have administrative privileges. Additionally, the attacker must know the username of a third account on the machine.

Security analysts characterize HiveLegacy as a powerful foundational technique that could potentially enable more sophisticated attacks. According to vulnerability researcher Will Dormann, the ability to modify an administrator’s registry hive from a non-admin account represents a significant security primitive, allowing attackers to execute arbitrary code with administrative privileges when the admin user logs in. Some researchers suggest the exploit could potentially be combined with other vulnerabilities to achieve direct administrative access without requiring knowledge of admin credentials.

NightmareEclypse, who has disclosed nine exploits to date, stated that the published proof-of-concept code was intentionally stripped down to limit malicious applications. The researcher has previously criticized Microsoft’s handling of vulnerability reports. Microsoft has indicated awareness of the issue and stated its preference that researchers follow coordinated disclosure procedures. Interim protective measures for Windows users include running detection scripts, restricting non-user account creation, monitoring the Profile Service process, and tracking registry activity related to user profiles.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI