Threat reportVulnerabilityTL-2026-0134

Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available, Forever-Day on Multiple Windows Versions

highACTIVE

Windows False File Immutability Kernel Exploit (TL-2026-0134), also tracked as Redux, is a high-severity software vulnerability, first published 2026-02-23. It has no confirmed attribution, affects Microsoft Windows 10 Enterprise LTSC 2021, maps to 22 MITRE ATT&CK techniques (T1003.001, T1003.002, T1005), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0134

Threat ID
TL-2026-0134
Also known as
Redux, PPLFault-Redux, GodFault-Redux, False File Immutability, FFI
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
enterprise, government, financial, healthcare, critical-infrastructure, defense
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Windows False File Immutability Kernel Exploit works

Elastic Security Labs disclosed a novel exploitation technique for the False File Immutability (FFI) vulnerability class in Windows. The exploit (Redux) leverages the built-in CloudFiles kernel driver (cldflt.sys) to bypass Windows Code Integrity protections without network redirectors. Public PoC enables arbitrary code execution as WinTcb-Light PPL and kernel memory compromise (GodFault-Redux). Microsoft only patched Windows 11 24H2 and Server 2025 — Windows 10 LTSC 2021, Server 2022, and Server 2019 remain permanently vulnerable as confirmed forever-days.

Elastic Security Labs researchers Gabriel Landau and collaborators published "The Immutable Illusion: Pwning Your Kernel with Cloud Files" on February 20, 2026, disclosing Redux — a novel advancement of the False File Immutability (FFI) vulnerability class originally disclosed in 2024.

## False File Immutability (FFI) Background

FFI is a Windows vulnerability class where the kernel and memory manager incorrectly assume certain files are immutable. When Windows loads an executable (EXE/DLL) into memory, it opens the file without FILE_SHARE_WRITE, making it appear immutable. The memory manager relies on this immutability — during page faults for memory-mapped executables, it reads directly from the backing file instead of maintaining a pagefile copy, assuming the file on disk cannot change.

The original FFI exploits (PPLFault, ItsNotASecurityBoundary) demonstrated that network redirectors (SMB) could be used to violate this immutability assumption because the remote server need not honor Windows file sharing semantics. An attacker-controlled SMB server could modify "immutable" files server-side, bypassing sharing restrictions.

## Redux: CloudFiles-Based Exploitation (No Network Required)

Redux eliminates the need for network redirectors entirely. The exploit leverages cldflt.sys (Cloud Files Mini-Filter Driver), a built-in Windows kernel driver that handles cloud file synchronization for applications like OneDrive.

### Technical Mechanism

1. **Cloud Sync Provider Registration**: The attacker registers as a Cloud Sync Provider using the Cloud Files API (cfapi), creating dehydrated placeholder files.

2. **Rehydration Callback Hijack**: When a Protected Process Light (PPL) loads a DLL from a CloudFiles-managed location, cldflt.sys invokes the attacker's rehydration callback to provide file contents.

3. **Initial Serve**: The callback serves the legitimate, signed DLL for Windows Code Integrity (CI) signature verification.

4. **Dehydrate/Rehydrate Cycle**: After CI verification passes, the attacker calls CfDehydratePlaceholder then CfHydratePlaceholder from a separate thread, resetting the file state within the CloudFilter driver.

5. **Payload Injection**: The second rehydration callback serves malicious payload content, overwriting the in-use DLL.

### Why It Works — Two Security Violations

**Violation of Immutability**: cldflt.sys uses FltWriteFileEx with FLTFL_IO_OPERATION_PAGING | FLTFL_IO_OPERATION_SYNCHRONOUS_PAGING flags to write file data. This bypasses the MmFlushImageSection check in NTFS that normally prevents writing to files mapped as executable images (SEC_IMAGE sections).

**Violation of the File Access Model**: cldflt.sys opens files using FltCreateFileEx2 with IO_IGNORE_SHARE_ACCESS_CHECK and only requests SYNCHRONIZE | FILE_READ_ATTRIBUTES | FILE_WRITE_ATTRIBUTES — not FILE_WRITE_DATA. Despite lacking write permissions, FltWriteFileEx succeeds because synchronous paging I/O bypasses access checks on the FILE_OBJECT.

### PPLFault vs Redux

- **PPLFault** (2023): Required network redirector (SMB server, either remote or loopback). More complex, detectable via SMB monitoring. - **Redux** (2024/2026): Self-contained, no network dependency. Uses only built-in Windows CloudFiles capability. Bypasses Microsoft's PPLFault-specific mitigation targeting network redirectors.

## Exploit Capabilities

**Redux (PPLFault-Redux)**: Achieves arbitrary code execution as WinTcb-Light Protected Process Light. Can dump LSASS credentials from PPL-protected processes.

**GodFault-Redux**: Leverages PPL access to compromise kernel memory, bypassing Windows Defender process protections. Can terminate normally-unkillable processes like MsMpEng.exe (Windows Defender).

## Affected and Fixed Versions

| OS | Lifecycle | Status | |---|---|---| | Windows 11 24H2 | Mainstream Support | FIXED | | Windows Server 2025 | Mainstream Support | FIXED | | Windows 10 LTSC 2021 | Mainstream Support | VULNERABLE (19044.6937, Feb 2026) | | Windows Server 2022 | Mainstream Support | VULNERABLE (20348.4773, Feb 2026) | | Windows Server 2019 | Extended Support | VULNERABLE (17763.8389, Feb 2026) |

Microsoft chose to only patch Windows 11 24H2 and Server 2025. Windows 10 LTSC 2021 and Server 2022 remain in Mainstream Support but are permanently vulnerable — confirmed forever-days with no planned fix.

## Disclosure Timeline

- 2024-02-14: Redux reported to MSRC - 2024-02-29: Windows Defender team engaged for coordinated disclosure - 2024-10-01: Windows 11 24H2 GA with fix (Philip Tsukerman independently discovered the variant) - 2026-02-20: Public disclosure by Elastic Security Labs with PoC release

## Mitigation

Elastic provides a filesystem minifilter that blocks IRP_MJ_ACQUIRE_FOR_SECTION_SYNCHRONIZATION operations meeting all criteria: requestor is PPL, PreviousMode is UserMode, page protection is executable or SEC_IMAGE, and file has Cloud Filter reparse tag. Built into Elastic Defend 8.14+. No Microsoft patch available for affected versions.

MITRE ATT&CK techniques used in TL-2026-0134

credential-access

T1003.001 LSASS Memory; T1003.002 Security Account Manager; T1556 Modify Authentication Process

collection

T1005 Data from Local System

defense-evasion

T1014 Rootkit; T1055.012 Process Hollowing; T1134 Access Token Manipulation

discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

privilege-escalation

T1068 Exploitation for Privilege Escalation

execution

T1106 Native API; T1203 Exploitation for Client Execution; T1569.002 Service Execution

initial-access

T1190 Exploit Public-Facing Application

impact

T1489 Service Stop

persistence

T1547.006 Kernel Modules and Extensions; T1574.001 DLL

defense-impairment

T1553.006 Code Signing Policy Modification; T1685 Disable or Modify Tools

resource-development

T1587.004 Exploits; T1588.005 Exploits

Affected products and versions in Windows False File Immutability Kernel Exploit

  • Microsoft — Windows 10 Enterprise LTSC 2021
    Vulnerable versions: 19044.6937 (February 2026, fully patched)
    Fixed in: No fix available — forever-day
  • Microsoft — Windows Server 2022
    Vulnerable versions: 20348.4773 (February 2026, fully patched)
    Fixed in: No fix available — forever-day
  • Microsoft — Windows Server 2019
    Vulnerable versions: 17763.8389 (February 2026, fully patched)
    Fixed in: No fix available — forever-day
  • Microsoft — Windows 11 24H2
    Vulnerable versions: Pre-GA builds
    Fixed in: 24H2 GA (October 2024)
  • Microsoft — Windows Server 2025
    Vulnerable versions: Pre-GA builds
    Fixed in: GA release

Remediation for Windows False File Immutability Kernel Exploit

Patches

  • Windows 11 24H2 — fixed at GA (October 2024)
  • Windows Server 2025 — fixed at GA
  • No patch available for Windows 10 LTSC 2021, Server 2022, or Server 2019 (forever-day)

Immediate actions

  • Upgrade to Windows 11 24H2 or Windows Server 2025 where the fix is available
  • Deploy Elastic Defend 8.14+ with FFI mitigation flag: windows.advanced.flags: e931849d52535955fcaa3847dd17947b
  • Monitor for Cloud Sync Provider registration from unexpected processes
  • Monitor for cldflt.sys rehydration activity on executable files (DLLs, EXEs)
  • Restrict CloudFiles API access via application control policies where possible

Workarounds

  • Elastic Defend minifilter mitigation (blocks exploit at filesystem level)
  • Disable OneDrive/CloudFiles sync on sensitive servers if not required
  • Restrict Cloud Sync Provider registration to known applications
  • Enable Credential Guard to limit LSASS dump impact

Longer-term hardening

  • Plan migration from Windows Server 2022/2019 and Windows 10 LTSC 2021 to patched versions
  • Deploy WDAC (Windows Defender Application Control) to restrict unsigned code execution
  • Implement Credential Guard to protect LSASS from memory dumping
  • Monitor for SEC_IMAGE section creation from CloudFiles-managed paths
  • Deploy EDR with specific FFI/Redux detection capabilities

Weaknesses (CWE) in Windows False File Immutability Kernel Exploit

CWE-693, CWE-284

Timeline of Windows False File Immutability Kernel Exploit

  • James Forshaw (Google Project Zero) publishes 'Windows Exploitation Tricks: Trapping Virtual Memory Access' — technique of combining CloudFiles with loopback SMB. Source: https://googleprojectzero.blogspot.com/2021/01/windows-exploitation-tricks-trapping.html
  • Gabriel Landau releases PPLFault exploit at Black Hat Asia 2023 — first FFI exploit using SMB network redirector to modify immutable DLLs in PPL processes. Source: https://github.com/gabriellandau/PPLFault
  • Elastic Security Labs discloses False File Immutability (FFI) vulnerability class with PPLFault and ItsNotASecurityBoundary exploits. Source: https://www.elastic.co/security-labs/false-file-immutability
  • Redux exploit reported to Microsoft Security Response Center (MSRC) by Elastic Security Labs.
  • Windows Defender team reaches out to Elastic for coordinated disclosure. Philip Tsukerman (Microsoft) independently discovered the variant.
  • FFI presented at BlueHat IL 2024. Source: https://www.youtube.com/watch?v=1LvOFU1u-eo
  • Elastic Defend 8.14 ships with built-in Redux mitigation filesystem minifilter.
  • Windows 11 24H2 reaches GA with Redux fix. Windows Server 2025 also fixed. Multiple Mainstream Support versions remain unpatched.
  • Elastic Security Labs publishes 'The Immutable Illusion: Pwning Your Kernel with Cloud Files' with full technical details and PoC release. Forever-day status confirmed for Windows 10 LTSC 2021, Server 2022, Server 2019. Source: https://www.elastic.co/security-labs/immutable-illusion
  • Multiple Windows versions in Mainstream Support remain permanently vulnerable. No Microsoft patch planned. PoC publicly available on GitHub.
  • As of 2026-05-29, the Redux/False File Immutability cldflt.sys exploit remains ACTIVE: Elastic Security Labs confirms Microsoft patched only Windows 11 24H2 and Server 2025, leaving Win10 LTSC 2021, Server 2022, and Server 2019 permanent forever-days with no planned fix, and the public PoC stays live. No CVE is assigned and there is no evidence of in-the-wild abuse; it is a coordinated research disclosure, but the unpatched build surface keeps the risk open.

Sources cited for Windows False File Immutability Kernel Exploit

Detection coverage for TL-2026-0134

As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0134 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats