Exploit mitigations (CFG, ACG, ASLR, CIG)
OS- and compiler-level defenses that constrain what a memory-corruption bug can actually do, even after it fires.
What you should already know
This topic is marked expert. Skim these first if any of them feel unfamiliar.
Related labs
Hands-on exercises for this area — in the browser or on a Windows machine.
View all labsGuided paths in this branch
Follow a short sequence step by step. Each path links to the first topic; use Read next on each page to continue.
Security deep dive
From identity (tokens) to object policy (DACL/SACL), through kernel access checks (SRM), ending with UAC and integrity boundaries.
Why it matters
Access checks and tokens assume the code running is the code you shipped. Exploit mitigations are the layer that assumes it might not be — that an attacker has already found a memory-corruption bug — and tries to make that bug far harder to turn into arbitrary code execution.
Mental model
Think of these as a sequence of narrowing hoops an exploit has to jump through after it's already found a bug: first it has to find anything useful in memory (ASLR), then it has to redirect execution somewhere useful (CFG), then whatever it redirects to has to not be new, attacker-written code (ACG/CIG) — any single mitigation defeats a large share of exploitation techniques without needing to know the specific bug.
How it works
- 1**ASLR** (Address Space Layout Randomization) randomizes where images, stacks, and heaps load on each boot/run, so an attacker can't hardcode addresses of useful gadgets or functions.
- 2**CFG** (Control Flow Guard) has the compiler emit a bitmap of valid indirect-call targets; at runtime, every indirect call is checked against that bitmap before it's taken, so corrupting a function pointer to point somewhere arbitrary no longer works.
- 3**ACG** (Arbitrary Code Guard) makes a process's memory pages mutually exclusive between writable and executable, and blocks remapping existing executable pages as writable — so even a successful exploit can't inject and run new shellcode in that process.
- 4**CIG** (Code Integrity Guard) restricts a process to loading only images signed by Microsoft (or an allow-listed signer), closing off the common bypass of loading an attacker-supplied but otherwise 'legitimate' DLL to get code execution without injecting raw shellcode.
- 5These are opt-in per process (via `SetProcessMitigationPolicy` / the image's load config, and increasingly on by default for browsers and other high-risk processes), not blanket OS behavior — which is why mitigation posture varies a lot between processes on the same machine.
Key terms
- CFG bitmap
- The compiler-generated table of valid indirect-call targets, checked by `ntdll!LdrpValidateUserCallTarget` on each guarded call.
- W^X
- Shorthand for 'writable xor executable' — the page-permission invariant ACG enforces.
- Mitigation policy
- The per-process bitmask of which of these defenses are active, queryable via `GetProcessMitigationPolicy`.
Why a browser renderer process looks so locked down
Modern browsers run their renderer (the process parsing untrusted web content) with ACG and CIG both enabled: even a successful memory-corruption exploit in page-rendering code can neither write executable shellcode nor load an unsigned helper DLL to escalate further — it's boxed in by policy, independent of the specific bug.
Common misconception
Treating these as interchangeable or as making a process 'unexploitable' — each closes off one specific technique, exploit chains routinely combine multiple bugs to route around a single missing mitigation, and none of them are a substitute for fixing the underlying memory-safety bug.
You should read next
Ranked from your current topic, related links, branch depth, and any active guided path.
expert
Kernel Patch Protection (PatchGuard) & HyperGuard
Periodic, obfuscated integrity checks that bugcheck the machine if core kernel state has been tampered with.
Related topic
beginner
Processes & threads
How Windows represents work, isolates applications, and schedules execution.
Related topic
intermediate
DLL loader, PEB, and module lists
How Windows loads shared libraries and tracks runtime module state.
Related topic
Related topics
Kernel Patch Protection (PatchGuard) & HyperGuard
Periodic, obfuscated integrity checks that bugcheck the machine if core kernel state has been tampered with.
Processes & threads
How Windows represents work, isolates applications, and schedules execution.
DLL loader, PEB, and module lists
How Windows loads shared libraries and tracks runtime module state.
Previous
Protected Processes & PPL
A process-launch-time trust label that restricts even SYSTEM-level handle access — not an access check.
Next
Application control: AppLocker & Software Restriction Policies
Policy that decides which executables, scripts, and installers are even allowed to run — enforced before the image loader finishes its job.