Inside Microsoft's plan to kill PPLFault
ID: a3384688-cd93-5cad-9428-e471b8081abc
STIX ID: report--a3384688-cd93-5cad-9428-e471b8081abc
Feed Name: Elastic Security Labs
Threat Score
This report analyzes two Windows security issues exploited by PPLFault and GodFault: an admin-to-PPL paging-based code-injection technique and a subsequent PPL-to-kernel escalation. It documents how build 25941 of Windows Insider Canary adds page-hash validation for remote-hosted images to mitigate the attack, describes debugging evidence of the failure mode, and notes public release of exploit code and mitigations (including NoFault and Elastic Defend updates).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
