started · updated
Microsoft patches Windows zero-day vulnerabilities
Microsoft is addressing multiple critical security vulnerabilities in its Windows operating system, including a zero-day flaw known as ‘ShieldBreak’ and another called ‘LegacyHive’ (CVE-2026-62832).
ShieldBreak, disclosed by a researcher using the pseudonym Nightmare Eclipse, targets Microsoft Defender. The vulnerability allows an attacker with local access to escalate their privileges to the SYSTEM level by exploiting the cloud-hydration process. Security experts Will Dormann and Kevin Beaumont have confirmed the exploit works on Windows 11 25H2 and Windows Server 2025. Nightmare Eclipse claims this flaw serves as a bypass for a previous patch related to the ‘RoguePlanet’ vulnerability.
Separately, Microsoft has released patches for the LegacyHive vulnerability, which involves improper link resolution within the Windows User Profile Service. This flaw could allow local attackers to gain administrator privileges.
These disclosures come amid a period of intense maintenance for Microsoft, which recently addressed hundreds of vulnerabilities during its August Patch Tuesday updates.
Entities
Kevin Beaumont · Microsoft · Nightmare Eclipse · Will Dormann · Windows 11 · Windows Defender · Windows Server 2025
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The ShieldBreak exploit was confirmed to work on the latest version of Windows 11. gr.pcmag.com
- [● 2 SOURCES] ShieldBreak affects Windows 11 25H2 and Windows Server 2025. gr.pcmag.com · technews.bg
- [○ 1 SOURCE] Microsoft has released security patches for the LegacyHive vulnerability, tracked as CVE-2026-62832. cybernoz.com
- [● 2 SOURCES] The ShieldBreak exploit allows a non-admin user to gain SYSTEM-level privileges by modifying the classes registry hive. cybernoz.com · www.memesita.com
- [○ 1 SOURCE] The LegacyHive vulnerability stems from improper link resolution in the Windows User Profile Service. cybernoz.com
- [○ 1 SOURCE] The ShieldBreak vulnerability is a zero-day that can bypass previous patches for the RoguePlanet vulnerability. www.memesita.com