<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb" -->

---
title: Windows zero-day dropped by repeat Microsoft critic on...
description: An anonymous researcher known as NightmareEclypse published a working proof-of-concept exploit (HiveLegacy/LegacyHive) targeting the Windows User Profile...
canonical: https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Windows zero-day dropped by repeat Microsoft critic on record patch day | daily.dev
og:description: An anonymous researcher known as NightmareEclypse published a working proof-of-concept exploit (HiveLegacy/LegacyHive) targeting the Windows User Profile...
og:url: https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb
og:image: https://api.daily.dev/og/posts/iiAt3klmB.png
og:image:alt: Windows zero-day dropped by repeat Microsoft critic on record patch day
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Windows zero-day dropped by repeat Microsoft critic on record patch day

**[Collections](https://daily.dev/sources/collections)** · 3 min read · 2 upvotes · 0 comments

## Summary

An anonymous researcher known as NightmareEclypse published a working proof-of-concept exploit (HiveLegacy/LegacyHive) targeting the Windows User Profile Service on the same day Microsoft released a record 570 patches. The exploit allows a low-privilege account to escalate to SYSTEM by modifying an administrator's registry hive. Microsoft issued an emergency out-of-band patch for CVE-2026-50656 (RoguePlanet, CVSS 7.8), which also affects Windows Defender. Security experts assessed the exploit as a useful post-compromise tool rather than a critical standalone threat, since it requires existing local access. The PoC was intentionally stripped down, making weaponization non-trivial. Organizations are advised to apply the Malware Protection Engine update and monitor for privilege escalation indicators.

## Content

A researcher going by Nightmare Eclipse dropped a working proof-of-concept exploit called LegacyHive on the same day Microsoft released a record 570 security patches in July 2026 - a timing that was almost certainly deliberate.

## What the vulnerability does

LegacyHive targets the Windows User Profile Service. It lets a low-privilege, non-admin user mount any other user's registry hive with full access. From there, an attacker can extract secrets or modify the classes registry hive so that when an administrator next logs in, they get code execution. The result is local privilege escalation on a fully patched Windows system.

No CVE has been assigned yet. Microsoft says it's still investigating.

## How dangerous is it, really?

Security experts are split on the severity. Kevin Beaumont confirmed the exploit works and published detection queries for Microsoft Defender for Endpoint. But the broader assessment is that LegacyHive is a useful post-compromise tool rather than the game-changer Nightmare Eclipse implied. The PoC was intentionally stripped down - it requires additional credentials to run - which limits how easily someone can weaponize it. You need local access first. It's not remotely exploitable on its own.

That said, "useful post-compromise tool" still means something. Once an attacker is on a machine, this gives them a reliable path to admin-level access.

## Who is Nightmare Eclipse?

This is the ninth zero-day released by the same anonymous researcher. Previous disclosures have targeted Windows components, Microsoft Defender, and BitLocker. Microsoft has previously threatened legal action against those causing harm to customers. The researcher has publicly criticized Microsoft's handling of bug reports, and the pattern of dropping exploits on Patch Tuesday - when Microsoft's security team is already stretched - reads as a deliberate provocation.

One of those earlier disclosures, RoguePlanet (CVE-2026-50656), was a high-severity elevation-of-privilege flaw in Windows Defender with a CVSS score of 7.8. Microsoft issued an emergency out-of-band patch for that one. Whether LegacyHive gets the same treatment remains to be seen.

## Patches: unofficial ones exist, official ones don't

Microsoft hasn't released a fix yet. In the meantime, ACROS Security's 0Patch platform is offering free unofficial micropatches for Windows 10 2004 and later, deployable without a system restart. It's not ideal, but it's something.

For detection, Beaumont's queries for Microsoft Defender for Endpoint are the most practical option right now. Organizations should also monitor for privilege escalation indicators and unusual registry hive access.

## Context: a busy Patch Tuesday

The July 2026 Patch Tuesday was already notable before LegacyHive dropped - 570+ fixes, more than 60 of them critical, covering everything from a DHCP privilege escalation to AI prompt injection in Edge and Copilot. ESET researchers also identified 11 Microsoft-signed boot loaders that can bypass Secure Boot protections, which is its own separate headache.

LegacyHive landing the same day added to an already chaotic week for Windows security teams.

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#windows](https://daily.dev/tags/windows), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Windows zero-day dropped by repeat Microsoft critic on record patch day","url":"https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb"},"datePublished":"2026-07-15T20:22:42.225Z","dateModified":"2026-07-21T08:49:53.266Z","description":"An anonymous researcher known as NightmareEclypse published a working proof-of-concept exploit (HiveLegacy/LegacyHive) targeting the Windows User Profile...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fa2a70d37426a5b4f3fd60a272ee69d8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fa2a70d37426a5b4f3fd60a272ee69d8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/windows-zero-day-dropped-by-repeat-microsoft-critic-on-record-patch-day-iiat3klmb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,windows,zero-day","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Windows zero-day dropped by repeat Microsoft critic on record patch day"}]}
```

