Elastic Security Labs detailed Redux, a Windows kernel-exploitation technique in the False File Immutability (FFI) class that abuses the Cloud Files subsystem and its cldflt.sys Cloud Filter driver. The technique defeats assumptions that executable image files cannot change once opened without write sharing: an attacker can alter DLL contents after they have been mapped and validated under Windows Code Integrity. Redux can elevate execution to WinTcb-Light through a protected process; when paired with GodFault-Redux, it can compromise kernel memory and terminate protected Microsoft Defender processes.
FFI stems from software treating file-sharing restrictions, such as those controlled through Windows file-opening APIs including CreateFileW, as a security boundary rather than ensuring underlying data remains immutable. Earlier FFI research demonstrated catalog-file swapping through a network redirector, enabling an administrator-level attacker to load an unsigned kernel driver; Microsoft addressed that path in Windows 11 23H2 through page locking and HVCI protections. Microsoft added a Redux mitigation in Windows 11 24H2 and Windows Server 2025, but Elastic reported the Cloud Files path remained exploitable on fully patched Windows 10 Enterprise LTSC 2021, Windows Server 2022, and Windows Server 2019 as of February 2026. Elastic Defend 8.14 and later offers an optional mitigation to block the exploit pattern.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
As of February 2026, Redux remained exploitable on fully patched Windows 10 Enterprise LTSC 2021, Windows Server 2022, and Windows Server 2019; researchers demonstrated LSASS dumping on Windows Server 2022 build 20348.4773.
Windows 11 24H2 reached general availability with a mitigation for the Redux Cloud Files exploitation technique.
Microsoft released KB5037771 generally for Windows 11 23H2, mitigating ItsNotASecurityBoundary by pinning mapped catalog pages with MmProbeAndLockPages.
Microsoft released KB5036980, a preview mitigation for ItsNotASecurityBoundary in Windows 11 23H2.
Microsoft's Windows Defender team contacted the researchers to coordinate disclosure of Redux. Microsoft researcher Philip Tsukerman had independently identified the issue, and a fix was in prerelease testing.
Elastic Security Labs reported the ItsNotASecurityBoundary Code Integrity catalog-processing vulnerability and its proposed minifilter mitigation to MSRC as VULN-119340.
Elastic Security Labs reported the Redux false-file-immutability issue affecting the Windows Cloud Files subsystem to Microsoft's Security Response Center.
Microsoft Defender released a mitigation enforcing dynamic page hashes for executable images loaded through network redirectors, breaking the PPLFault exploitation path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceelastic.co
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.