LegacyHive Is a New Windows Zero-Day Targeting the User Profile Service
LegacyHive runs on every supported version of Windows, July's patch included. Nightmare Eclipse released it anyway, then tore out the pages that would let anyone turn it into a weapon.
When we last checked in, Nightmare Eclipse had just cancelled a mass zero-day dump scheduled for July 14, then un-cancelled the break, and teased a drop of "really interesting and possibly insanely controversial findings" for the same date anyway. The date has now come and gone, and the drop landed on schedule. What makes it worth a second look, though, is less what was in it than what was deliberately left out.
On July 14, the researcher published LegacyHive[1], a privilege-escalation vulnerability in the Windows User Profile Service that lets a standard user mount another user's registry hive into their own session. In plain terms, a low-privilege account can reach straight into another user's live secrets, configuration, and stored credentials, an administrator's included. The underlying flaw works exactly as advertised: the proof of concept runs on every currently supported version of Windows desktop and server, including machines carrying the July 2026 security patch. What shipped, though, is not the exploit Nightmare Eclipse actually had. The GitHub release is a deliberately crippled version, stripped of the parts that would make it usable by anyone without their own research chops, and the README says so outright: "The PoC was stripped down as an attempt to prevent public exploitation."
Stripped for parts
The gap between this release and the ones that came before it is hard to miss, and none of it is accidental. The original, unmodified exploit required no extra credentials and could load any registry hive, not just the user-class hive the public version is limited to. The public version is practically tied in knots: it needs a second set of user credentials and an administrator's username just to run, and if it succeeds, it merely mounts the target hive into the current user's classes root. That hands a user a genuine step up in privilege, nowhere near the god-mode access the un-crippled exploit originally boasted. To get from the PoC to a working weapon, the README notes dryly, "you would need some brain cells."
That makes this a different kind of release from the ones that put Nightmare Eclipse on the map in April and May, when fully weaponized exploits went straight to GitHub alongside messages meant to needle Microsoft's Security Response Center. Those drops were functional attacks, ready to be picked up and run: BlueHammer turned Defender into a side door, RedSun added another route to SYSTEM, UnDefend let attackers switch the same product off, and YellowKey bypassed BitLocker with a USB stick. LegacyHive is built to be studied rather than run, closer to a blueprint with half the pages torn out than to a loaded weapon.
By their own telling, the reasons for pulling their punches were practical more than principled. In a blog post leading up to the release, they called it "the least interesting and least impactful bug" they had dropped since they started, adding that Microsoft had "legit just stopped pocking me and pissing me off" and that they were "conserving some energy." A separate post, dated July 8, read more like a confession: "Feeling depressed recently, I just wish if my brain power was used for good and not this. Dropping 0days is truly agonizing." Nobody outside their head can say whether that mood shaped the stripped-down release or just happened to coincide with it. Either way, the result is a working vulnerability disclosed in a way that gives defenders a head start over attackers, which the earlier drops pointedly did not.
The day LegacyHive dropped, the researcher posted a one-liner: "I wonder how many sweats were waiting for today." It is a jab at the exploit brokers, the zero-day buyers, and the attackers who had been counting on another weaponized release. They got a research artifact instead. The taunt lands the way most of their writing lands, and it makes clear the stripped-down release was deliberate. Nightmare Eclipse knew exactly what they were holding back, and who would go home empty-handed.
Look closely at the rest of the month, and it becomes clear this restraint wasn't isolated to LegacyHive. On July 9, five days before the drop, Nightmare Eclipse published findings on Windows Defender rather than an exploit for it. The most theatrical is a way to make Defender fill a machine's own disk: when it scans a file from a remote SMB share, it caches a local copy of any attached Alternate Data Stream with no size limit. Serve a malicious executable trailed by a massive Zone.Identifier stream, then hang the connection, and Defender will quietly choke the disk to zero free space, enough to leave Windows falling over. They reproduced it on Windows 11 25H2 and Windows Server 2025. As with anything posted to an anonymous blog, the specifics are unconfirmed. Either way, the posture matches LegacyHive's: map a weakness in public, and let the exposure do the work a weapon used to.
The pattern that matters
By the book, Nightmare Eclipse is still not a coordinated discloser. They publish on their own schedule, reserve no CVE, give the vendor no advance notice, sign their posts with PGP keys, and host mirrors on a domain called Church of Malware. What they do not do is cash in. They have not sold any of this to the brokers or governments who would pay a fortune for a working Windows zero-day; every drop goes out free and in public, reaching defenders and attackers on the same day. Their grievance is simple: they say they took the official reporting route first and got brushed off[9]. Microsoft rejects that, insisting the researcher never properly reported the bugs in the first place. What is not in question is what came next: the company threatened them with criminal prosecution[7], then backed off once the security community turned on it[8]. Seen from there, the public drops look less like a grudge than the one lever that has reliably made Microsoft act.
The restraint matters for a reason the earlier drops obscured: Nightmare Eclipse can choose. The mass dump threatened for July 14 did not happen, and the exploit that did ship was built to be read, not run. The researcher who spent April and May proving they could put Microsoft on the back foot spent July proving they could choose not to. It's a fragile sort of optimism, resting entirely on the mood of an anonymous person under no obligation to keep showing restraint. Still, in a story that has been nothing but escalation since April, movement in the other direction is worth noticing.
There is no Patch Tuesday fix for LegacyHive yet, and the vulnerability works on fully patched systems. The defensive guidance, as it has been since the first drop, is to do what you can do: apply patches as they arrive, harden BitLocker with PINs and firmware passwords, and accept that for now the goal is to shrink the exposure rather than close it. The eclipse did not pass, and it has not gone away. But for the first time since April, it let a little light through.
Sources
- LegacyHive public disclosure (PGP-signed)ProjectNightcrawler
- LegacyHive: Windows user profile service arbitrary hive load EoPGitHub (MSNightmare)
- Some interesting findings in Windows Defender (PGP-signed)ProjectNightcrawler
- Ranting Post (PGP-signed)ProjectNightcrawler
- July updates (PGP-signed)ProjectNightcrawler
- Too many sweats (PGP-signed)ProjectNightcrawler
- Microsoft under fire for threatening security researcher with criminal investigationTechCrunch
- Microsoft reaches for olive branch after public dustup with 0-day researcherThe Register
- The Security Nightmare That Eclipsed All Otherscasually.onl
