Particle.news
Download on the App Store

Researcher Publishes LegacyHive PoC That Escalates Privileges on Patched Windows

Microsoft is investigating LegacyHive with no CVE or security update issued.

Overview

  • Hours after Microsoft’s July 2026 Patch Tuesday, researcher Chaotic Eclipse published a proof‑of‑concept called LegacyHive that targets the Windows User Profile Service to load other users’ registry hives and escalate privileges.
  • The released PoC was deliberately stripped down and, as published, requires prior access to the machine plus an extra set of user credentials to work.
  • The researcher says an unreleased original version did not need added credentials and could load any hive, a detail that raises the risk of faster weaponization if the code is extended or reversed.
  • Microsoft has been notified and is investigating but has not assigned a CVE, posted an advisory, or issued a patch, leaving defenders to rely on detection rules and mitigations developed by security teams.
  • LegacyHive continues a string of public zero‑day disclosures by Chaotic Eclipse since April that have pressured Microsoft to issue emergency fixes and prompted agencies and enterprises to scramble to assess post‑compromise risks.