LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 · LevelBlue SpiderLabs · Severity: CRITICAL
Nightmare-Eclipse released a new zero-day vulnerability called LegacyHive, affecting the Windows User Profile component. This Local Privilege Escalation allows attackers to access other users' hives and sensitive data. The vulnerability is currently unpatched and poses a significant risk to Windows systems.
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.
Key Takeaways
- Nightmare-Eclipse released LegacyHive, a zero-day LPE vulnerability in Windows.
- The flaw targets Windows User Profile, allowing access to other users' hives.
- Attackers can steal application data and Windows Explorer history via this bug.