Affected Systems

Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.

Exploitation Status

Public PoC exploit available since July 2026. Exploit requires valid local user credentials to escalate privileges to administrator. No confirmed active exploitation in the wild reported, but PoC is functional and verified by multiple researchers.

Business Impact

Local privilege escalation vulnerability allows authenticated attackers with low-privilege credentials to gain administrator access and modify other users' registry data. Exploitation requires existing local account access, reducing immediate risk from external attackers but critical in environments with compromised user accounts or insider threats. Microsoft patched in August 2026 Patch Tuesday (CVE-2026-62832). Part of a series of nine zero-days disclosed by same researcher since April 2026, indicating potential for coordinated attack chains.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Apply Microsoft August 2026 Patch Tuesday updates immediately to remediate CVE-2026-62832 on all Windows 10 (2004+) and Windows Server 2022+ systems
  • Deploy Microsoft Defender for Endpoint detection queries published by Kevin Beaumont to identify potential LegacyHive exploitation attempts in your environment
  • Review Windows Event Logs for unusual User Profile Service activity and unauthorized registry hive modifications, particularly in HKEY_CLASSES_ROOT
  • Audit local user accounts and enforce least privilege principles to limit exposure; remove unnecessary local accounts with interactive logon rights
  • Monitor for related zero-days from same researcher (ShieldBreak, BlueHammer, RedSun, UnDefend) that remain unpatched and may be chained with LegacyHive