> How clean is it?
It's as clean as any official Win32 API which uses their privilege system to restrict/allow accesses to each and any bit of information on the process state and/or memory.
> Can you simply exec the result?
This is possible using CreateThread() [1] which creates a remote thread inside another process execution context.
[1] https://docs.microsoft.com/en-us/windows/win32/api/processth...
> Glibc used to have unexec()
My understanding is that unexec() was more about making a snapshot of the whole process state to an executable on disk.