Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released patches for the Windows zero-day vulnerability LegacyHive, now tracked as CVE-2026-62832, after it was disclosed with a proof-of-concept exploit. The flaw affects the Windows User Profile Service and can let authenticated local attackers gain administrator privileges; Microsoft and other researchers also provided detection and unofficial mitigation guidance. #LegacyHive #CVE-2026-62832 #NightmareEclipse #WindowsUserProfileService

Keypoints

  • Microsoft patched the LegacyHive zero-day in its August 2026 Patch Tuesday updates.
  • The flaw is tracked as CVE-2026-62832 and affects the Windows User Profile Service.
  • An authenticated attacker with local credentials can gain administrator privileges through the exploit.
  • Nightmare Eclipse released a proof-of-concept shortly after the July 2026 Patch Tuesday.
  • Kevin Beaumont published detection queries, and ACROS Security released unofficial 0Patch fixes.

Read More: https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/