Microsoft Patches LegacyHive Windows Zero-Day Vulnerability
TL;DR. Microsoft issued security patches for the LegacyHive Windows zero-day vulnerability, CVE-2026-62832, disclosed by a security researcher. - The flaw allowed local attackers to gain administrator privileges via improper link resolution in the User Profile Service. - Microsoft released the fix as part of its August Patch Tuesday updates, tracking it as CVE-2026-62832. - Cybersecurity experts confirmed the exploit's functionality and released detection queries prior to the official patch.
- Microsoft released security patches for the LegacyHive Windows zero-day vulnerability.
- The vulnerability, CVE-2026-62832, allows local privilege escalation in Windows User Profile Service.
- A security researcher, 'Nightmare Eclipse', publicly disclosed the flaw and a proof-of-concept exploit.
- The fix was part of Microsoft's August Patch Tuesday, with unofficial patches previously available.
Sources
- Microsoft patches LegacyHive Windows zero-day vulnerability — bleepingcomputer.com
- tomshardware.com — tomshardware.com