LegacyHive Mounts Another Account’s Registry Hive Into a Session You Control, and the Write That Sets It Up Happens Where Your Auditing Isn’t
A working Windows exploit dropped roughly half an hour after July’s Patch Tuesday, with no CVE and no Microsoft advisory. LegacyHive edits a registry hive while it is unmounted, so live registry auditing never sees the write, and the payoff is another account’s hive mounted into a session the attacker controls. Here is what actually fires, what the first published rule got wrong, and which controls cut the class.