LegacyHive Mounts a Target’s Hive Into the Helper’s Session
A working Windows exploit dropped roughly half an hour after July’s Patch Tuesday, with no CVE and no Microsoft advisory. LegacyHive edits a registry hive while it is unmounted, so live registry auditing never sees the write, and the payoff is another account’s hive mounted into a session the attacker controls. Here is what actually fires, what the first published rule got wrong, and which controls cut the class.