Microsoft added Code Integrity page-hash validation for executable images hosted on remote devices in Windows Insider Canary build 25941, mitigating the PPLFault zero-day. The flaw abused the Cloud Filter API and unvalidated paging of SMB-hosted DLLs, allowing an attacker who already held administrator privileges to inject unsigned code into highly privileged WinTcb-Light Protected Process Light (PPL) processes.
PPLFault could bypass LSA protection and terminate or blind endpoint detection and response products. Its companion GodFault exploit chained PPLFault with a PPL-to-kernel vulnerability to alter kernel memory and gain physical-memory read/write access. The new validation causes altered remotely hosted payload DLLs to fail integrity checks, preventing injection; the change was initially released in an Insider pre-release build, with general-availability rollout not assured at the time.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft released Windows Insider Canary build 25941 with Code Integrity page-hash validation for executable images on remote devices. The change prevents altered SMB-hosted payload DLL pages used by PPLFault from passing validation.
Elastic publicly released the PPLFault and GodFault exploits at Black Hat Asia. It also released NoFault, a mitigation intended to block network-redirected DLL loads into PPL processes.
Gabriel Landau of Elastic Security reported PPLFault, an administrator-to-Protected Process Light exploit, and GodFault, a PPL-to-kernel exploit, to the Microsoft Security Response Center under VULN-074311 and provided proof-of-concept source code.
Microsoft patched the Windows Code Integrity time-of-check/time-of-use vulnerability used by PPLFault. The patch addressed the technique that enabled code execution at the WinTcb-Light protection level and protected-process memory dumping.
Elastic Defend version 8.9.0 and later blocks PPLFault exploitation.
According to Elastic, MSRC declined to take action on the reported vulnerabilities, although the Windows Defender team expressed interest in them.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcegithub.com
Open sourcemicrosoft.com
Open sourcei.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.