Elastic Security Labs disclosed two Windows zero-day exploit paths that enable attackers with local administrator privileges to bypass Protected Process Light (PPL) protections and escalate from PPL to kernel-level execution. The PPLFault and GodFault techniques can disable Windows Defender and other AV/EDR controls without a bring-your-own-vulnerable-driver (BYOVD) component, undermining controls intended to restrict administrator-driven kernel tampering.
The techniques operate despite Windows defenses including Driver Signing Enforcement, Secure Boot, and the Vulnerable Driver Blocklist, which limit untrusted kernel drivers but do not prevent this driverless exploit chain. Microsoft reportedly declined to patch the issues because exploitation requires administrator access; Elastic released the NoFault kernel driver as an interim PPL mitigation and integrated protection into Elastic Endpoint/Defend version 8.9.0 and later, while the underlying kernel escalation remained unpatched.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
After the researcher announced a Black Hat Asia 2023 presentation on PPLdump, the Windows Defender team contacted them for details, indicating MSRC had not informed that team of the PPL bypass.
The researcher reported an administrator-to-Protected Process Light bypass and a PPL-to-kernel exploit path to Microsoft Security Response Center under case VULN-074311, including source code for both exploits.
Microsoft introduced Driver Signing Enforcement with Windows Vista x64 to restrict the loading of arbitrary kernel drivers.
The researcher released the NoFault kernel driver as an interim mitigation for the PPL exploit, and Elastic Endpoint/Defend 8.9.0 and later incorporated NoFault-based protection. The mitigation breaks the exploit chain but does not remediate the underlying kernel vulnerability.
The researcher released the PPLFault administrator-to-PPL exploit and the GodFault administrator-to-kernel exploit chain, along with a driverless EDRSandBlast variant integrating PPLFault that was demonstrated disabling the Windows Defender driver.
MSRC declined further action because the attack chain required administrator privileges and did not meet its threshold for immediate servicing.
Microsoft began enabling the Vulnerable Driver Blocklist by default with Windows 11 version 22H2.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourceelastic.co
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.