
Hours after Microsoft released its record July Patch Tuesday updates, a security researcher known online as “Nightmare Eclipse” published a new unpatched Windows exploit called LegacyHive. The flaw lives in the Windows User Profile Service — a core system component that manages user accounts — and allows a regular user account to tamper with an administrator’s settings in the Windows registry. Independent security researcher Will Dormann described the capability as “a pretty powerful primitive,” meaning it can be a stepping stone toward full system takeover.
This is the ninth unpatched Windows exploit this researcher has released publicly without working with Microsoft first. Previous releases included BlueHammer, YellowKey, GreenPlasma, and others — several of which were later picked up by ransomware groups. LegacyHive has no patch today, and Microsoft has not yet publicly commented on a timeline for a fix.
How to check if you’re affected
Affected devices are any Windows computers — including fully up-to-date systems — because LegacyHive is unpatched even after July’s updates. To reduce your risk while waiting for a patch:
- Use standard user accounts for everyday tasks instead of an administrator account. LegacyHive requires local access, so attackers need to already be running code on your machine.
- Avoid installing software from untrusted sources — this is the most common way attackers get a foothold before exploiting privilege escalation flaws.
- Keep Windows Update current so that when Microsoft releases a fix, you receive it immediately.
Watch for a future Windows Update that specifically addresses a vulnerability in the Windows User Profile Service (ProfSvc).
