Threat reportVulnerabilityTL-2026-0134
Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available, Forever-Day on Multiple Windows Versions
Windows False File Immutability Kernel Exploit (TL-2026-0134), also tracked as Redux, is a high-severity software vulnerability, first published 2026-02-23. It has no confirmed attribution, affects Microsoft Windows 10 Enterprise LTSC 2021, maps to 22 MITRE ATT&CK techniques (T1003.001, T1003.002, T1005), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0134
- Threat ID
- TL-2026-0134
- Also known as
- Redux, PPLFault-Redux, GodFault-Redux, False File Immutability, FFI
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- enterprise, government, financial, healthcare, critical-infrastructure, defense
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Windows False File Immutability Kernel Exploit works
Elastic Security Labs disclosed a novel exploitation technique for the False File Immutability (FFI) vulnerability class in Windows. The exploit (Redux) leverages the built-in CloudFiles kernel driver (cldflt.sys) to bypass Windows Code Integrity protections without network redirectors. Public PoC enables arbitrary code execution as WinTcb-Light PPL and kernel memory compromise (GodFault-Redux). Microsoft only patched Windows 11 24H2 and Server 2025 — Windows 10 LTSC 2021, Server 2022, and Server 2019 remain permanently vulnerable as confirmed forever-days.
Elastic Security Labs researchers Gabriel Landau and collaborators published "The Immutable Illusion: Pwning Your Kernel with Cloud Files" on February 20, 2026, disclosing Redux — a novel advancement of the False File Immutability (FFI) vulnerability class originally disclosed in 2024.
## False File Immutability (FFI) Background
FFI is a Windows vulnerability class where the kernel and memory manager incorrectly assume certain files are immutable. When Windows loads an executable (EXE/DLL) into memory, it opens the file without FILE_SHARE_WRITE, making it appear immutable. The memory manager relies on this immutability — during page faults for memory-mapped executables, it reads directly from the backing file instead of maintaining a pagefile copy, assuming the file on disk cannot change.
The original FFI exploits (PPLFault, ItsNotASecurityBoundary) demonstrated that network redirectors (SMB) could be used to violate this immutability assumption because the remote server need not honor Windows file sharing semantics. An attacker-controlled SMB server could modify "immutable" files server-side, bypassing sharing restrictions.
## Redux: CloudFiles-Based Exploitation (No Network Required)
Redux eliminates the need for network redirectors entirely. The exploit leverages cldflt.sys (Cloud Files Mini-Filter Driver), a built-in Windows kernel driver that handles cloud file synchronization for applications like OneDrive.
### Technical Mechanism
1. **Cloud Sync Provider Registration**: The attacker registers as a Cloud Sync Provider using the Cloud Files API (cfapi), creating dehydrated placeholder files.
2. **Rehydration Callback Hijack**: When a Protected Process Light (PPL) loads a DLL from a CloudFiles-managed location, cldflt.sys invokes the attacker's rehydration callback to provide file contents.
3. **Initial Serve**: The callback serves the legitimate, signed DLL for Windows Code Integrity (CI) signature verification.
4. **Dehydrate/Rehydrate Cycle**: After CI verification passes, the attacker calls CfDehydratePlaceholder then CfHydratePlaceholder from a separate thread, resetting the file state within the CloudFilter driver.
5. **Payload Injection**: The second rehydration callback serves malicious payload content, overwriting the in-use DLL.
### Why It Works — Two Security Violations
**Violation of Immutability**: cldflt.sys uses FltWriteFileEx with FLTFL_IO_OPERATION_PAGING | FLTFL_IO_OPERATION_SYNCHRONOUS_PAGING flags to write file data. This bypasses the MmFlushImageSection check in NTFS that normally prevents writing to files mapped as executable images (SEC_IMAGE sections).
**Violation of the File Access Model**: cldflt.sys opens files using FltCreateFileEx2 with IO_IGNORE_SHARE_ACCESS_CHECK and only requests SYNCHRONIZE | FILE_READ_ATTRIBUTES | FILE_WRITE_ATTRIBUTES — not FILE_WRITE_DATA. Despite lacking write permissions, FltWriteFileEx succeeds because synchronous paging I/O bypasses access checks on the FILE_OBJECT.
### PPLFault vs Redux
- **PPLFault** (2023): Required network redirector (SMB server, either remote or loopback). More complex, detectable via SMB monitoring. - **Redux** (2024/2026): Self-contained, no network dependency. Uses only built-in Windows CloudFiles capability. Bypasses Microsoft's PPLFault-specific mitigation targeting network redirectors.
## Exploit Capabilities
**Redux (PPLFault-Redux)**: Achieves arbitrary code execution as WinTcb-Light Protected Process Light. Can dump LSASS credentials from PPL-protected processes.
**GodFault-Redux**: Leverages PPL access to compromise kernel memory, bypassing Windows Defender process protections. Can terminate normally-unkillable processes like MsMpEng.exe (Windows Defender).
## Affected and Fixed Versions
| OS | Lifecycle | Status | |---|---|---| | Windows 11 24H2 | Mainstream Support | FIXED | | Windows Server 2025 | Mainstream Support | FIXED | | Windows 10 LTSC 2021 | Mainstream Support | VULNERABLE (19044.6937, Feb 2026) | | Windows Server 2022 | Mainstream Support | VULNERABLE (20348.4773, Feb 2026) | | Windows Server 2019 | Extended Support | VULNERABLE (17763.8389, Feb 2026) |
Microsoft chose to only patch Windows 11 24H2 and Server 2025. Windows 10 LTSC 2021 and Server 2022 remain in Mainstream Support but are permanently vulnerable — confirmed forever-days with no planned fix.
## Disclosure Timeline
- 2024-02-14: Redux reported to MSRC - 2024-02-29: Windows Defender team engaged for coordinated disclosure - 2024-10-01: Windows 11 24H2 GA with fix (Philip Tsukerman independently discovered the variant) - 2026-02-20: Public disclosure by Elastic Security Labs with PoC release
## Mitigation
Elastic provides a filesystem minifilter that blocks IRP_MJ_ACQUIRE_FOR_SECTION_SYNCHRONIZATION operations meeting all criteria: requestor is PPL, PreviousMode is UserMode, page protection is executable or SEC_IMAGE, and file has Cloud Filter reparse tag. Built into Elastic Defend 8.14+. No Microsoft patch available for affected versions.
MITRE ATT&CK techniques used in TL-2026-0134
credential-access
T1003.001 LSASS Memory; T1003.002 Security Account Manager; T1556 Modify Authentication Process
collection
defense-evasion
T1014 Rootkit; T1055.012 Process Hollowing; T1134 Access Token Manipulation
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
privilege-escalation
T1068 Exploitation for Privilege Escalation
execution
T1106 Native API; T1203 Exploitation for Client Execution; T1569.002 Service Execution
initial-access
T1190 Exploit Public-Facing Application
impact
persistence
T1547.006 Kernel Modules and Extensions; T1574.001 DLL
defense-impairment
T1553.006 Code Signing Policy Modification; T1685 Disable or Modify Tools
resource-development
Affected products and versions in Windows False File Immutability Kernel Exploit
- Microsoft — Windows 10 Enterprise LTSC 2021
Vulnerable versions: 19044.6937 (February 2026, fully patched)
Fixed in: No fix available — forever-day - Microsoft — Windows Server 2022
Vulnerable versions: 20348.4773 (February 2026, fully patched)
Fixed in: No fix available — forever-day - Microsoft — Windows Server 2019
Vulnerable versions: 17763.8389 (February 2026, fully patched)
Fixed in: No fix available — forever-day - Microsoft — Windows 11 24H2
Vulnerable versions: Pre-GA builds
Fixed in: 24H2 GA (October 2024) - Microsoft — Windows Server 2025
Vulnerable versions: Pre-GA builds
Fixed in: GA release
Remediation for Windows False File Immutability Kernel Exploit
Patches
- Windows 11 24H2 — fixed at GA (October 2024)
- Windows Server 2025 — fixed at GA
- No patch available for Windows 10 LTSC 2021, Server 2022, or Server 2019 (forever-day)
Immediate actions
- Upgrade to Windows 11 24H2 or Windows Server 2025 where the fix is available
- Deploy Elastic Defend 8.14+ with FFI mitigation flag: windows.advanced.flags: e931849d52535955fcaa3847dd17947b
- Monitor for Cloud Sync Provider registration from unexpected processes
- Monitor for cldflt.sys rehydration activity on executable files (DLLs, EXEs)
- Restrict CloudFiles API access via application control policies where possible
Workarounds
- Elastic Defend minifilter mitigation (blocks exploit at filesystem level)
- Disable OneDrive/CloudFiles sync on sensitive servers if not required
- Restrict Cloud Sync Provider registration to known applications
- Enable Credential Guard to limit LSASS dump impact
Longer-term hardening
- Plan migration from Windows Server 2022/2019 and Windows 10 LTSC 2021 to patched versions
- Deploy WDAC (Windows Defender Application Control) to restrict unsigned code execution
- Implement Credential Guard to protect LSASS from memory dumping
- Monitor for SEC_IMAGE section creation from CloudFiles-managed paths
- Deploy EDR with specific FFI/Redux detection capabilities
Weaknesses (CWE) in Windows False File Immutability Kernel Exploit
Timeline of Windows False File Immutability Kernel Exploit
- James Forshaw (Google Project Zero) publishes 'Windows Exploitation Tricks: Trapping Virtual Memory Access' — technique of combining CloudFiles with loopback SMB. Source: https://googleprojectzero.blogspot.com/2021/01/windows-exploitation-tricks-trapping.html
- Gabriel Landau releases PPLFault exploit at Black Hat Asia 2023 — first FFI exploit using SMB network redirector to modify immutable DLLs in PPL processes. Source: https://github.com/gabriellandau/PPLFault
- Elastic Security Labs discloses False File Immutability (FFI) vulnerability class with PPLFault and ItsNotASecurityBoundary exploits. Source: https://www.elastic.co/security-labs/false-file-immutability
- Redux exploit reported to Microsoft Security Response Center (MSRC) by Elastic Security Labs.
- Windows Defender team reaches out to Elastic for coordinated disclosure. Philip Tsukerman (Microsoft) independently discovered the variant.
- FFI presented at BlueHat IL 2024. Source: https://www.youtube.com/watch?v=1LvOFU1u-eo
- Elastic Defend 8.14 ships with built-in Redux mitigation filesystem minifilter.
- Windows 11 24H2 reaches GA with Redux fix. Windows Server 2025 also fixed. Multiple Mainstream Support versions remain unpatched.
- Elastic Security Labs publishes 'The Immutable Illusion: Pwning Your Kernel with Cloud Files' with full technical details and PoC release. Forever-day status confirmed for Windows 10 LTSC 2021, Server 2022, Server 2019. Source: https://www.elastic.co/security-labs/immutable-illusion
- Multiple Windows versions in Mainstream Support remain permanently vulnerable. No Microsoft patch planned. PoC publicly available on GitHub.
- As of 2026-05-29, the Redux/False File Immutability cldflt.sys exploit remains ACTIVE: Elastic Security Labs confirms Microsoft patched only Windows 11 24H2 and Server 2025, leaving Win10 LTSC 2021, Server 2022, and Server 2019 permanent forever-days with no planned fix, and the public PoC stays live. No CVE is assigned and there is no evidence of in-the-wild abuse; it is a coordinated research disclosure, but the unpatched build surface keeps the risk open.
Sources cited for Windows False File Immutability Kernel Exploit
- The Immutable Illusion: Pwning Your Kernel with Cloud Files — Elastic Security Labs
- False File Immutability (original disclosure) — Elastic Security Labs
- Redux PoC — GitHub (gabriellandau)
- PPLFault PoC — GitHub (gabriellandau)
- FileTestDriver experiments — GitHub (gabriellandau/BlogExamples)
- BlueHat IL 2024 — FFI Presentation
- PPLdump Is Dead. Long Live PPLdump — Black Hat Asia 2023
- Windows Exploitation Tricks: Trapping Virtual Memory Access — Google Project Zero (James Forshaw)
- Cloud Files API Portal — Microsoft Learn
- ItsNotASecurityBoundary PoC — GitHub (gabriellandau)
- NoFault Mitigation PoC — GitHub (gabriellandau/Redux)
- Elastic Defend Advanced Policy — FFI Mitigation
Detection coverage for TL-2026-0134
As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0134 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.