A security researcher who has been locked in an increasingly public dispute with Microsoft has released details of another Windows zero-day vulnerability, adding a fresh chapter to a controversy involving vulnerability disclosure, customer security and the boundaries of independent security research.
The researcher, who operates under the name Nightmare Eclipse and has also been known as Chaotic Eclipse, disclosed the Windows zero-day dubbed LegacyHive shortly after Microsoft’s July security updates were released.
The vulnerability affects the Windows User Profile Service and could allow someone who already has limited access to a computer to gain greater privileges on the system. Researchers who independently examined the flaw said it worked against Windows machines that were fully updated at the time of disclosure.
Microsoft subsequently confirmed that it was aware of the reported vulnerability and was investigating whether the claims were valid and which products could be affected.
The disclosure is particularly notable because it follows months of tension between Microsoft and Nightmare Eclipse over the public release of previously unknown Windows vulnerabilities.
Windows Zero-Day Known as LegacyHive
LegacyHive was publicly disclosed in mid-July, shortly after Microsoft released its monthly Patch Tuesday security updates.
At the time, the vulnerability did not have a publicly assigned CVE identifier, the standard tracking number normally used for security flaws.
Security researchers testing the issue described it as a local privilege-escalation vulnerability.
In practical terms, this means it is not generally viewed as a flaw that allows an unknown attacker anywhere on the internet to instantly take control of a Windows computer. An attacker would first need some form of access to the affected machine.
If successfully abused after that initial access, however, the vulnerability could potentially give an attacker greater permissions, making it easier to interfere with sensitive parts of the operating system.
That distinction makes LegacyHive important for organisations because attackers frequently combine multiple vulnerabilities and techniques during a wider cyberattack.
Researcher Limited Parts of the Public Demonstration
Nightmare Eclipse released a proof-of-concept alongside the disclosure, but reports indicate that the publicly shared version was deliberately limited compared with the researcher’s original demonstration.
The restrictions were intended to make the flaw harder to turn immediately into a practical attack.
That differs from several earlier disclosures in the dispute, when working proof-of-concept material was released publicly and some vulnerabilities were later observed being abused in real-world attacks.
F5 Labs reported in June that three earlier vulnerabilities associated with Nightmare Eclipse disclosures — BlueHammer, RedSun and UnDefend — had been exploited after their publication.
The history surrounding those earlier bugs is one reason the latest Windows zero-day has attracted significant attention from the cybersecurity community.
Microsoft Says It Is Investigating LegacyHive
Microsoft told BleepingComputer after the disclosure that it was aware of LegacyHive and was investigating the reported security issue.
The company also reiterated its support for coordinated vulnerability disclosure, the industry practice in which researchers privately report vulnerabilities to a software vendor and allow time for investigation and patch development before detailed information becomes public.
Microsoft has argued that this approach helps protect users because software companies can prepare fixes before attackers learn enough about a vulnerability to misuse it.
Its Microsoft Security Response Center made the same argument in May when responding to the earlier series of Nightmare Eclipse disclosures.
Microsoft said several zero-day vulnerabilities had been published without first being provided to the company, creating what it described as unnecessary risk for customers.
That statement helped trigger the wider confrontation.
Microsoft Faced Backlash Over Legal Action Language
The dispute escalated dramatically in late May after Microsoft discussed the possibility of legal action in the context of harmful vulnerability disclosures.
The wording was widely interpreted within the security community as a warning directed at Nightmare Eclipse, who had already released several previously unknown vulnerabilities affecting Windows, Microsoft Defender and BitLocker.
The response was immediate.
Some security professionals argued that threatening researchers could discourage legitimate vulnerability research and damage the relationship between software companies and the people who discover weaknesses in their products.
Microsoft later clarified its position.
On June 1, the company said it had no intention of taking action against people merely for conducting or publishing legitimate security research. Microsoft added that law enforcement involvement would instead be considered where individuals broke the law and caused real harm to customers.
That clarification is important because Microsoft’s earlier language is sometimes described simply as a direct legal threat against all researchers who publish vulnerabilities.
The company’s later position was more limited.
Nightmare Eclipse Has Released Several Windows Flaws
LegacyHive is only the latest vulnerability associated with Nightmare Eclipse.
During 2026, the researcher publicly disclosed a series of security issues given names including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma and RoguePlanet.
The vulnerabilities affected different areas of Microsoft’s ecosystem, including Windows components, Microsoft Defender and BitLocker.
Some have since been patched.
Microsoft addressed GreenPlasma, MiniPlasma and YellowKey in its June security updates, while RoguePlanet was fixed through an update to the Microsoft Malware Protection Engine in July.
The repeated disclosures have transformed what would normally be separate security incidents into a broader debate about how technology companies and independent researchers should handle serious vulnerabilities.
Why Zero-Day Vulnerabilities Matter
A zero-day is generally a security weakness that becomes known before users have an official fix available.
That creates a difficult period for defenders.
Security teams may know that a vulnerability exists but have limited options for eliminating the underlying problem until the software developer releases an update.
The risk can increase further when enough technical information becomes publicly available for criminals to understand how the weakness might be abused.
This is why coordinated disclosure has become common across the cybersecurity industry.
Researchers privately notify vendors, vendors investigate and prepare fixes, and details are normally made public after users have had an opportunity to update their systems.
The model is not perfect.
Researchers sometimes complain that companies take too long to respond, reject valid reports or provide insufficient communication. Vendors, meanwhile, argue that publishing an unpatched flaw too quickly can put millions of customers at unnecessary risk.
The Microsoft-Nightmare Eclipse dispute demonstrates how badly that relationship can deteriorate when trust breaks down.
Windows Zero-Day Raises Responsible Disclosure Debate
The LegacyHive case therefore goes beyond a single Windows vulnerability.
It raises a fundamental question about who carries responsibility when a serious security problem is discovered.
Researchers argue that public scrutiny can pressure companies to fix vulnerabilities that might otherwise receive insufficient attention.
Software companies counter that releasing details before a patch exists can effectively give malicious actors a roadmap to weaknesses affecting ordinary users and businesses.
Both concerns have become more urgent as cybercriminals move increasingly quickly after new vulnerabilities become public.
Microsoft’s May statement emphasised that vulnerability research should be coordinated so fixes and protections can be prepared before detailed public disclosure.
Nightmare Eclipse’s disclosures, by contrast, have repeatedly challenged that conventional process.
Fully Updated Windows Systems Were Reportedly Affected
Another reason LegacyHive attracted attention was its timing.
The vulnerability appeared immediately after Microsoft’s July security updates, and independent researchers reported that machines considered fully patched at that point were still affected.
That does not mean Windows updates are ineffective.
Security updates address vulnerabilities already identified and fixed by Microsoft. A genuinely new zero-day can still affect a completely updated computer because the flaw was not known or resolved when the update was produced.
For users, the episode highlights why cybersecurity involves more than simply installing patches.
Updates remain essential, but organisations also depend on restricted user privileges, endpoint monitoring, backups, network security and other layers of protection to reduce the consequences of newly discovered vulnerabilities.
Researchers Independently Confirmed the Bug
LegacyHive was not based solely on claims from Nightmare Eclipse.
Independent security professionals examined the vulnerability following its release and reported that the issue could be reproduced.
BleepingComputer reported that vulnerability analyst Will Dormann confirmed the security implications after testing the proof-of-concept, while cybersecurity researcher Kevin Beaumont also confirmed that the vulnerability worked and published information intended to help organisations detect suspicious activity associated with it.
That independent verification strengthened the case that Microsoft had a genuine security issue to investigate.
Microsoft did not dismiss the report. Instead, it said it was examining both its validity and potential impact.
Microsoft Has Been Patching Earlier Disclosures
Despite the public confrontation, Microsoft has continued investigating and fixing vulnerabilities previously disclosed by Nightmare Eclipse.
RoguePlanet, for example, affected Microsoft Defender and was assigned CVE-2026-50656.
Microsoft addressed that vulnerability in July through an update to the Microsoft Malware Protection Engine.
Several other vulnerabilities from the same researcher were patched during Microsoft’s June security cycle.
That pattern demonstrates the unusual nature of the dispute.
Microsoft has strongly criticised the way the vulnerabilities were disclosed while simultaneously treating a number of the underlying technical findings seriously enough to issue security fixes.
The Bigger Issue Is Trust
Cybersecurity depends heavily on cooperation between researchers and technology companies.
No major software platform is completely free from vulnerabilities.
Independent researchers therefore play an important role by finding weaknesses before criminals do and reporting them to companies capable of fixing the problem.
Companies, in turn, need systems that researchers trust.
That includes clear reporting channels, timely communication and transparent decisions around vulnerability recognition and bug-bounty programmes.
When that relationship works, users may never know how many serious vulnerabilities were discovered and repaired before criminals could exploit them.
When it fails, disputes can spill into public view, as Microsoft’s confrontation with Nightmare Eclipse demonstrates.
Security Researchers Also Carry Responsibility
The controversy does not place responsibility entirely on software vendors.
Publishing detailed information about an unpatched vulnerability can create real security consequences.
Earlier vulnerabilities associated with Nightmare Eclipse were reportedly exploited shortly after public disclosure, reinforcing concerns about how quickly criminal groups can react when new attack opportunities become available.
Researchers therefore face their own difficult balance.
Public disclosure can hold companies accountable, but releasing too much information too quickly can expose people and organisations that had no involvement in the dispute.
LegacyHive appears to reflect some recognition of that problem because the publicly released demonstration was intentionally restricted to make straightforward weaponisation more difficult.
Windows Users Should Focus on Official Security Updates
For ordinary Windows users, the dispute between Microsoft and Nightmare Eclipse may seem distant, but the underlying security issues are relevant.
The most practical response is not panic.
Users and businesses should continue installing official Windows and Microsoft security updates as they become available, since those updates include fixes for previously disclosed vulnerabilities.
Microsoft’s August 2026 Patch Tuesday alone addressed hundreds of vulnerabilities across its products, including one vulnerability that the company said had already been exploited in the wild.
Maintaining updated systems remains one of the most effective ways of reducing exposure to known security weaknesses.
Users should also be cautious about unknown software and suspicious files, while organisations should maintain layered security controls and monitor Microsoft’s official security guidance.
Windows Zero-Day Dispute Is Far From Over
LegacyHive shows that the conflict surrounding Microsoft’s vulnerability-disclosure process has not disappeared.
Nightmare Eclipse has continued publishing security research despite account suspensions, public criticism and the earlier controversy over Microsoft’s legal language.
Microsoft, meanwhile, continues to argue that serious vulnerabilities should be reported privately before technical details are released publicly.
The company has also clarified that legitimate researchers are not its legal target, while reserving the right to work with law enforcement when malicious activity causes harm.
LegacyHive therefore represents more than another Windows zero-day.
It is the latest example of a difficult cybersecurity problem with no simple solution: researchers need effective ways to hold powerful software companies accountable, while vendors need enough time to protect millions of users before dangerous vulnerabilities become widely understood.
Finding that balance requires trust.
The continuing dispute between Microsoft and Nightmare Eclipse shows what can happen when that trust disappears.








