Nightmare Eclipse, a prolific Microsoft-taunting hacker, had warned of a “Bone Crushing” vulnerability and exploit proof-of-concept to be disclosed this month, timed to maximize exposure around Patch Tuesday. Instead, a limited elevation of privilege vulnerability named “LegacyHive” was released, which exploits the Windows User Profile Service but requires standard user credentials and another username to escalate privileges by mounting a target user hive.
The hacker claimed to have deliberately toned down the proof-of-concept to make it less annoying for Microsoft and harder for attackers to weaponize, stripping it so it no longer allows loading any hive without additional credentials. Security researchers confirmed the PoC, and Microsoft issued its standard response, adding LegacyHive to a list of previous vulnerabilities like RoguePlanet and BlueHammer that were patched the following month.
It remains unclear if this was the promised bone-crushing exploit with restrictions applied, or another exaggeration of capabilities. No significant damage occurred this month, though past exploits by the hacker have been quickly adopted by real attackers, potentially prompting the toned-down release due to harm to innocent users.