LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 · LevelBlue SpiderLabs · Severity: CRITICAL
Nightmare-Eclipse, a researcher also known as Chaotic Eclipse and Dead Eclipse, has disclosed LegacyHive, a new unpatched Windows Local Privilege Escalation (LPE) vulnerability. This marks the ninth zero-day vulnerability released by the researcher. LegacyHive targets the Windows User Profile component, which handles the loading and unloading of user profiles. Exploitation of this vulnerability allows attackers to load other users’ hives, potentially gaining access to sensitive data such as application information and Windows Explorer history. The vulnerability affects Windows systems, though specific versions impacted have not been detailed. The release of LegacyHive underscores the ongoing risks posed by unpatched vulnerabilities in widely used operating systems like Windows. While Nightmare-Eclipse has provided a stripped-down proof-of-concept (PoC), the lack of a patch leaves systems exposed to potential exploitation. This vulnerability is particularly concerning for organizations and individuals relying on Windows for critical operations, as it could enable unauthorized access to sensitive user data. The disclosure highlights the challenges faced by cybersecurity teams in addressing zero-day vulnerabilities and the importance of timely patching and proactive security measures.
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.
Key Takeaways
- Nightmare-Eclipse released LegacyHive, a ninth unpatched Windows zero-day LPE vulnerability.
- LegacyHive targets Windows User Profile, enabling attackers to load other users' hives.
- Exploitation grants access to application data and Windows Explorer history.