Four Weeks Ago a Third Party Patched LegacyHive Because Microsoft Wouldn't. Yesterday Microsoft Shipped the Fix — and Credited an Anonymous Researcher.
- Patrick Duggan
- 2 hours ago
- 4 min read
This is a follow-through post. We wrote LegacyHive twice while it had no CVE and no patch, and the story just closed. Here is the whole arc with dates, because the arc is the point.
The timeline
July 14, 2026. Microsoft ships its largest Patch Tuesday ever — 570 fixes, two already exploited in the wild.
July 15, hours later. A researcher who goes by Nightmare Eclipse (also Chaotic Eclipse, known around Redmond as a serial tormentor) publishes a working proof-of-concept for a Windows flaw with no CVE, no advisory and no security update. It affects fully patched machines. It is called LegacyHive.
July 17. We publish on it, and temper it: "LegacyHive Is Real, and Smaller Than the Headline." The bug lives in the Windows User Profile Service — the component that loads your registry hive at logon. It lets a standard user who already has code execution mount another user's registry hive under their own profile, reach secrets that should be walled off, or alter what runs at that user's next logon. Real, useful in a chain, not the haymaker the coverage promised.
July 21. A week on, still no Microsoft fix. 0patch ships a free, unofficial micropatch that installs without a reboot. We publish that, and say plainly that the more interesting story is the second one: the fix for a Windows zero-day arrived from a third party before it arrived from Windows.
August 11, 2026. Microsoft patches it in the August Patch Tuesday as [CVE-2026-62832](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-62832) — improper link resolution before file access in the Windows User Profile Service, elevation of privilege to administrator, CVSS 7.8, rated Important.
Twenty-eight days from public PoC to vendor fix. Twenty-one of those days, the only patch available anywhere came from a third party.
The part that shouldn't pass without comment
Microsoft has not credited Nightmare Eclipse. The advisory tags CVE-2026-62832 as reported by an anonymous researcher.
The researcher published the PoC publicly rather than through coordinated disclosure, and reasonable people can argue that forfeits the acknowledgement. But the sequence is what it is: a named individual published the flaw, a third party fixed it for free, the vendor shipped four weeks later, and the credit line reads anonymous.
We have written before about convicted hackers being rehired while builders get ignored. This is a milder version of the same instinct — the acknowledgement is the cheapest thing in the entire process, and it is the thing that gets withheld.
What this closes, and what it says about the no-CVE tier
We run a standing beat on fixes that ship with no CVE and no security label, because the label failure is itself the story. LegacyHive is now a complete worked example of that beat, start to finish:
For 28 days the bug had no CVE, so it did not exist to any vulnerability scanner, any KEV process, any patch-compliance dashboard or any risk register. During that window it was fully public, had a working PoC, and affected fully patched machines. Every control an enterprise owns reported clean.
Then Microsoft assigned CVE-2026-62832, and overnight the identical bug became visible — trackable, scannable, reportable, prioritisable. Nothing about the flaw changed. Only the label.
That is the whole argument for the beat in one CVE number. If your programme's field of view is defined by identifiers the vendor chooses to issue, then the vendor decides what you are allowed to see, and the gap between "exploitable" and "visible" is measured in weeks.
It is the same shape as two other things we published this week: City-Forum, reading Salesforce and ServiceNow portals worldwide for seventeen months through guest access with no CVE because nothing broke; and Plug and Pwn, turning a forged USB descriptor into SYSTEM through Windows Plug and Play working exactly as designed. Three stories, one lesson — the catalogue is not the territory.
What to do
Patch [CVE-2026-62832](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-62832) on the normal cycle. It is a local privilege escalation, Important, 7.8 — genuinely not an emergency, exactly as we said in July when everyone else was calling it bone-shattering.
Keep the micropatch vendors in your toolkit. 0patch shipped 21 days before Microsoft. For a shop that cannot wait a month on a public PoC, that is not a curiosity, it is a control.
Track the unlabelled. If your process only ingests CVEs, build a second lane for publicly-demonstrated flaws that have no identifier yet. That lane is where this bug lived for four weeks, and it is where the next one is living right now.
Ninety-five percent, as always. We called LegacyHive smaller than the headline on July 17 and we stand by that — the CVSS came in at 7.8, which is roughly where we put it. Being right about a bug being less serious than the noise is a less popular call than the reverse, and it is the one worth making.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=four-weeks-ago-a-third-party-patched-legacyhive-because-microsoft-wouldn-t-yesterday-microsoft-ship




Comments