LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service — Threadlinqs Intelligence
As of 2026-07-15, LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service is a high-severity vulnerability threat attributed to Nightmare-Eclipse (Chaotic Eclipse, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1351 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
Attribution: Nightmare-Eclipse (Chaotic Eclipse · UNKNOWN
Security researcher Nightmare-Eclipse (GitHub: MSNightmare), a self-identified grudge actor known as 'Chaotic Eclipse'/'Dead Eclipse' who has released six Windows zero-days since April 2026, publicly
LegacyHive is a proof-of-concept elevation-of-privilege primitive targeting the Windows User Profile Service (ProfSvc), the component responsible for loading and unloading a signed-in user's registry hives (NTUSER.DAT and UsrClass.dat) at logon/logoff. The published technique allows a low-privileged, standard (non-administrator) local user to cause a hive belonging to a different local user account to be mounted underneath the attacker's own HKEY_CURRENT_USER\Software\Classes root, i.e., their per-user 'classes root'. Once mounted there, the victim's hive data — including UsrClass.dat contents such as COM/shell-extension registrations, file-association state, and other shell configuration — becomes readable/writable in a context the attacker fully controls, without the attacker ever needing SYSTEM or Administrator privileges to trigger the load.
The vulnerability class is not novel in kind: Microsoft has previously shipped at least three related fixes for User Profile Service / registry-hive-loading elevation-of-privilege bugs — MS15-003 (ProfSvc could be tricked, via a Shell Folders registry key change plus an NTFS junction, into opening an arbitrary UsrClass.dat belonging to another user), MS16-111 (RegLoadAppKey / NtLoadKeyEx hive-attachment-point abuse), and MS16-124 (NtLoadKeyEx read-only-hive-to-write-mode fallback with process impersonation leading to EoP). LegacyHive appears to be a modern recurrence of the same underlying pattern in current, fully-patched Windows builds, indicating the User Profile Service's hive-load path has not been durably hardened against this class of abuse.
The researcher, operating under the handles Nightmare-Eclipse, 'Chaotic Eclipse', and 'Dead Eclipse' (blog: deadeclipse666.blogspot.com), announced ahead of time that a 'major exploit targeting Microsoft products' would land on 2026-07-14, having previously claimed unspecified 'chains' were preventing an earlier release. On that date the LegacyHive GitHub repository (github.com/MSNightmare/LegacyHive, mirrored at git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, MIT-licensed, C++) appeared, initially as a placeholder ('N/A' README, license file only, 2 commits), with full source (LegacyHive.cpp) and documentation following roughly 11 hours later (4 commits total). The researcher deliberately stripped the released PoC down from its original, more dangerous form: the internal/original version could reportedly load an arbitrary registry hive with no extra credentials, while the public build is artificially restricted to the UsrClass.dat hive only and requires the operator to already possess a second standard user's password plus the username of a third account (which can be an administrator account) before the primitive will fire. This restriction is a self-imposed abuse-reduction measure by the discloser, not a mitigation implemented by Microsoft.
LegacyHive is the latest in a six-exploit campaign by the same actor since April 2026, all targeting Microsoft Windows: BlueHammer (CVE-2026-33825, a TOCTOU race in Windows Defender's file-remediation engine using an NTFS junction to redirect a Defender write to C:\Windows\System32 for SYSTEM code execution — patched 2026-04-14, added to CISA KEV 2026-04-22/23, and confirmed by CISA on 2026-06-30 to be under active exploitation by ransomware gangs), RedSun (an alternate Defender privilege-escalation path to SYSTEM, silently patched, no CVE assigned), UnDefend (a Defender-disruption tool that weakens detection while masking reported system health), YellowKey (a BitLocker bypass affecting TPM-only configurations, exploitable with physical device access), GreenPlasma (a partial Windows LPE PoC released as a building block rather than a complete exploit), and MiniPlasma (an LPE tied to a supposedly-already-fixed 2020-era vulnerability, confirmed by researchers to still work on fully patched Windows 11 as of May 2026). The actor has publicly stated a grievance-driven motive ('someone violated ou
Target sectors: all sectors any organization running multi-user windows hosts
Target regions: global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1588.006, T1587.004, T1585.001, T1078.003, T1068, T1548, T1012, T1033, T1069, T1552.002