Join us at Black Hat and discover how we’re reshaping the cybersecurity landscape. Learn More

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.

What’s peculiar about this month’s drop is that the proof-of-concept (PoC) was stripped, deterring the public from exploiting it. On LegacyHive’s GitHub page, Nightmare-Eclipse shared that the original PoC did not need user credentials to work and allowed any hive, including those of administrators, to be loaded. “Any hive could be loaded using this vulnerability, but you would need some brain cells to make the PoC do it,” writes Nightmare-Eclipse.

LegacyHive, which Nightmare-Eclipse publicly shared after Microsoft released this month’s batch of hefty security updates, works on all Windows desktop and server versions, even those that have applied the July 2026 Patch Tuesday update.

Prior to releasing LegacyHive, Nightmare-Eclipse published back-to-back vulnerability drops for June 2026. The first of which was RoguePlanet, a race condition exploit that can spawn a command shell with SYSTEM-level privileges, giving threat actors unfettered access to a vulnerable machine.

GreatXML, on the other hand, is an exploit that allows attackers to bypass BitLocker, a built-in Windows feature that protects data from unauthorized access via full-disc encryption. According to Nightmare-Eclipse, this exploit will work on any system that has previously performed a Microsoft Defender Offline scan, which is typically recommended to users who suspect a malware infection or those who want to ensure that an endpoint is thoroughly clean following a malware outbreak.

We covered the technical mechanisms behind both vulnerabilities in our blog.

As of writing, Microsoft has yet to publicly acknowledge or release a patch for LegacyHive.

About the Author

Pauline Bolaños is Security Content Researcher at LevelBlue SpiderLabs. She has seven years of experience as a cybersecurity writer, covering diverse security topics including malware, vulnerabilities, AI, and the cloud. Follow Pauline on LinkedIn.

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo