Zero‑day exploit disclosed as Microsoft issues record patches
Originally published Jul 15, 2026
By Dan Goodin · Ars Technica
AI-generated summary based on Ars Technica · Aggregated by OffScreenSpace · Human-reviewed and approved on Jul 15, 2026
Key points
- HiveLegacy targets a flaw in Windows User Profile Service.
- Low‑privilege accounts can alter an admin's registry hive using the exploit.
- Microsoft is aware of the vulnerability and is investigating.
- Detection scripts and hardening measures are available to mitigate risk.
A researcher known as NightmareEclypse released proof‑of‑concept code for a new Windows elevation‑of‑privilege vulnerability dubbed HiveLegacy. The exploit lets a low‑privilege account modify the classes registry hive of an administrator, potentially granting de facto admin rights without needing the attacker’s own admin credentials. Microsoft confirmed it is investigating the report and emphasized its preference for coordinated disclosure. In the meantime, independent security researchers have provided detection scripts and mitigation steps such as restricting local non‑user account creation and monitoring the User Profile Service for unexpected hive loads.
Read the original story: Ars Technica — by Dan Goodin