logo

Inside Microsoft's plan to kill PPLFault

ID: a3384688-cd93-5cad-9428-e471b8081abc

STIX ID: report--a3384688-cd93-5cad-9428-e471b8081abc

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-09-15

Date Updated: 2026-04-27

...
...

This report analyzes two Windows security issues exploited by PPLFault and GodFault: an admin-to-PPL paging-based code-injection technique and a subsequent PPL-to-kernel escalation. It documents how build 25941 of Windows Insider Canary adds page-hash validation for remote-hosted images to mitigate the attack, describes debugging evidence of the failure mode, and notes public release of exploit code and mitigations (including NoFault and Elastic Defend updates).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.