0patch ships free unofficial fix for LegacyHive zero-day
ACROS Security (0patch) shipped free micropatches for the unpatched LegacyHive LPE — Windows 10 2004 and Server 2019 up. Microsoft is still investigating.
The patch conversation on LegacyHive just changed. Microsoft still hasn’t shipped a fix and still hasn’t assigned a CVE, but ACROS Security has published free 0patch micropatches for the unpatched Windows local privilege escalation that Nightmare Eclipse dropped a PoC for last week. If you were sitting on the same “no patch, just detection” posture I laid out on Sunday, that posture is no longer the only option.
What changed
- Coverage. ACROS says the micropatches cover Windows 10 2004 and later on the client side, and Windows Server 2019 and later on the server side. That is broad — effectively every currently-supported Windows build that meets the affected-version description in the BleepingComputer writeup.
- Cost. Free. You register a 0patch account, install the 0patch Agent, and the fix deploys to any endpoint on your tenant. No reboot.
- Not a Microsoft fix. This is third-party in-memory patching from ACROS, not an MSRC-blessed KB. Your governance stack — change control, compliance auditors, EDR vendor’s compatibility posture — needs to treat it as such.
- Still no CVE. Microsoft’s on-record statement is unchanged: aware, investigating, no advisory. Kevin Beaumont has independently confirmed the exploit works and published Defender for Endpoint hunt queries. In-wild exploitation is still not confirmed by any named source.
Priority order — updated
Sunday’s list assumed no patch. That assumption is now partially wrong. Rework it in this order:
- Decide whether 0patch is in scope for your fleet at all. This is a policy call, not a technical one. If you already run 0patch (a lot of shops do — it’s been the go-to for orphaned Windows 7/Server 2008 boxes for years), rolling out the LegacyHive micropatch is a config change and you should have done it before you finished this paragraph. If you don’t run 0patch, decide today whether you’re willing to bring in an unofficial in-memory patching agent as a stopgap. If the answer is no, skip to step 3 and keep the detection posture from Sunday.
- If yes — deploy narrowly first. Shared endpoints where the LegacyHive detonation pattern actually matters: RDP jump boxes, VDI images, kiosks, shared engineer workstations, anywhere a helpdesk or endpoint-management account routinely logs in interactively alongside standard users. Those are where an unpatched LPE turns into tenant admin. Cover them first; general-fleet rollout is a lower priority.
- Keep the detection running either way. Beaumont’s Defender queries are still useful — micropatches suppress the vulnerable code path, but detection on the surrounding technique (standard-user writes to
usrclass.datfrom processes that shouldn’t be touching it, followed by an admin interactive logon on the same host) is the layer that catches whatever the next disclosed hive-abuse trick looks like. - Don’t let the 0patch fix quiet the interactive-admin conversation. LegacyHive is one bug in a family. The reason it’s dangerous — helpdesk and management accounts holding interactive sessions on endpoints standard users also touch — is a standing tax on your privilege model that a third-party micropatch does not pay off. LAPS on local admin, remote-management tooling that doesn’t drop interactive sessions, tighter logon-target restrictions on Tier-0 accounts. Same list as Sunday.
- Wait for MSRC before you retire the workaround. When Microsoft ships the real fix, uninstall or supersede the 0patch coverage in a normal patch window and go back to the vendor-signed KB as source of truth. Track MSRC, not press coverage.
Where this fits
Micropatches from 0patch have a track record — they’re the reason a lot of the still-running Server 2008 and Windows 7 fleet nobody wants to admit exists is not currently on fire — but they are not a substitute for a vendor advisory. They’re a bridge you cross when the vendor’s timeline has slipped past what you can carry with detection alone, and you go back to the vendor road as soon as it’s paved. On LegacyHive, that bridge exists now. Whether you’re willing to walk it is a call your change board makes, not one your EDR does.
Two more things worth naming plainly. First: no confirmed exploitation in the wild is not the same as no exploitation. The public PoC still requires standard-user credentials on the target, which is a low bar on any domain, and Nightmare Eclipse admitted the credential-free version was held back. Assume someone is going to reconstruct it. Second: Microsoft has had this since July 17 and has not yet decided whether to ship. That is the number worth tracking. Every day past today that the MSRC advisory doesn’t appear, the calculus for turning on a third-party stopgap on shared endpoints gets a little easier.
Found this useful? Share it.


