The conflict between the ‘security researcher’ Nightmare Eclipse and Microsoft continues to escalate. Shortly after the latest patch Tuesday, the developer published a new zero-day vulnerability for Windows that allows extensive system access.
A now infamous ‘security researcher’ has made good on his previous threat to Microsoft. Just a few hours after the extensive July patch day, the developer published another zero-day vulnerability for Windows after several holes. The code targets the Windows User Profile Service and enables local privilege escalation on affected systems.
The vulnerability is called LegacyHive and affects the way the operating system loads user-specific registry databases at system startup. If an attack is successful, a standard user can mount another account’s settings into their own session. In a worst-case scenario, this grants read and write access to an administrator’s data, which can make a complete system takeover easier.
The one from Nightmare Eclipse published proof of concept was deliberately severely restricted. The public version requires additional credentials and is limited to a specific file. According to the developer, the full exploit should work without these hurdles and can load any data.
The attacked system service is essential for the correct provision of user profiles after registration. Because it runs with high system privileges, it represents an attractive target for attackers. Zero-day vulnerabilities like LegacyHive are particularly critical because they become known to the public and potential criminals before the manufacturer has been able to develop a working protection. The current release right after the July patch day is no coincidence.
There is a personal conflict behind this. The developer accuses Microsoft of not taking him seriously and not fairly remunerating the security holes he submitted. After a series of bans on developer platforms such as GitHub and GitLab, Nightmare Eclipse threatened to release the zero-day exploit immediately after a patch day at the end of May.
The particularly treacherous thing about LegacyHive is its supposed effectiveness on all currently supported versions of Windows, even if the latest security update is installed. IT security teams warn that skilled attackers could quickly reconstruct the missing parts of the code. In the past, similar gaps were actively exploited by the researcher within a few days. A small bright spot in the current situation is that the restricted published code at least prevents simple free riders from immediate attacks.
Nevertheless, the approach puts Microsoft under a lot of pressure because there is no official patch yet. The company is currently investigating the incident and, as in the past, emphasizes the importance of coordinated disclosure of vulnerabilities in order not to unnecessarily endanger end users.
GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…
An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…
The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…
A patent that has surfaced suggests that Nintendo could be working on a universal dock…
The dates for all upcoming sales on Valve's gaming platform Steam in the first half…
Spotify is unlocking a previous premium feature for all users. From now on, managed user…