Windows zero-day lets attackers hijack user accounts

Published July 9, 2026

A newly found Windows flaw lets attackers hijack user accounts by tricking the system into loading fake account files. Microsoft has not yet patched it.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
Microsoft
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker sends a specially crafted file that tricks Windows into loading fake user account data, letting them take over the account.

What to do

Check whether the installed Microsoft version is older than the fixed version in the vendor advisory or current release.

Update Windows immediately through the normal update tool.' Microsoft has not yet fixed this flaw, so wait for their official patch.

Technical details

A critical zero-day vulnerability in Windows allows attackers to hijack user accounts by exploiting the Windows User Profile Service (ProfSvc), a core system component managing user profiles and permissions. Dubbed LegacyHive, the flaw enables arbitrary hive file loading, granting attackers elevated privileges, effectively taking over affected accounts. The proof-of-concept was published by researcher Chaotic Eclipse (Nightmare-Eclipse) under identifier NEWS-bbee8814f8d02d2c33. No fixed versions or CVSS score were disclosed in the source.