Technology

Windows gap: Hackers dupe Microsoft with ninth zero-day exploit

The conflict between the ‘security researcher’ Nightmare Eclipse and Microsoft continues to escalate. Shortly after the latest patch Tuesday, the developer published a new zero-day vulnerability for Windows that allows extensive system access.

New Windows exploit released

A now infamous ‘security researcher’ has made good on his previous threat to Microsoft. Just a few hours after the extensive July patch day, the developer published another zero-day vulnerability for Windows after several holes. The code targets the Windows User Profile Service and enables local privilege escalation on affected systems.

The vulnerability is called LegacyHive and affects the way the operating system loads user-specific registry databases at system startup. If an attack is successful, a standard user can mount another account’s settings into their own session. In a worst-case scenario, this grants read and write access to an administrator’s data, which can make a complete system takeover easier.

The one from Nightmare Eclipse published proof of concept was deliberately severely restricted. The public version requires additional credentials and is limited to a specific file. According to the developer, the full exploit should work without these hurdles and can load any data.

Exact timing

The attacked system service is essential for the correct provision of user profiles after registration. Because it runs with high system privileges, it represents an attractive target for attackers. Zero-day vulnerabilities like LegacyHive are particularly critical because they become known to the public and potential criminals before the manufacturer has been able to develop a working protection. The current release right after the July patch day is no coincidence.

There is a personal conflict behind this. The developer accuses Microsoft of not taking him seriously and not fairly remunerating the security holes he submitted. After a series of bans on developer platforms such as GitHub and GitLab, Nightmare Eclipse threatened to release the zero-day exploit immediately after a patch day at the end of May.

Danger to patched systems

The particularly treacherous thing about LegacyHive is its supposed effectiveness on all currently supported versions of Windows, even if the latest security update is installed. IT security teams warn that skilled attackers could quickly reconstruct the missing parts of the code. In the past, similar gaps were actively exploited by the researcher within a few days. A small bright spot in the current situation is that the restricted published code at least prevents simple free riders from immediate attacks.

Nevertheless, the approach puts Microsoft under a lot of pressure because there is no official patch yet. The company is currently investigating the incident and, as in the past, emphasizes the importance of coordinated disclosure of vulnerabilities in order not to unnecessarily endanger end users.

Recent Posts

GameStop boss: Game disks are completely irrelevant

GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…

3 hours ago

Linux kernel update leads to performance decline on AMD GPUs

An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…

3 hours ago

Tasteless but expensive: luxury gold cell phones honor Messi and Ronaldo

The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…

3 hours ago

Switch 1 & 2: Nintendo may be working on a smart universal dock

A patent that has surfaced suggests that Nintendo could be working on a universal dock…

3 hours ago

Steam Sales: Valve reveals dates for all discount promotions until July 2027

The dates for all upcoming sales on Valve's gaming platform Steam in the first half…

3 hours ago

Spotify: Former premium function is now free for all users

Spotify is unlocking a previous premium feature for all users. From now on, managed user…

4 hours ago