Microsoft to add Exploit Guard feature in this fall's Creators Update for Windows to help manage EMET-like exploit mitigations app by app
The built-in exploit mitigations are getting stronger and easier to configure. — The Windows 10 Fall Creators Update will include EMET …
Context & Ripple Effects
Microsoft has been steadily pulling security tooling into Windows itself: SmartScreen drive-by blocking for IE11 and Edge arrived at the end of 2015, and the Creators Update's enterprise push added IT management and hardening features a year later. Exploit Guard extends that arc by taking EMET-style exploit mitigations out of a separate download and making them configurable app by app inside the OS.
The timing matters because the attack surface keeps proving real: Microsoft patched an RCE flaw in its Malware Protection Engine used across nearly every version of Windows just weeks before this announcement, and another critical one in the same component followed in April 2018.
First-order effects
- IT admins managing Windows 10 fleets can configure exploit mitigations per application through Exploit Guard in the Fall Creators Update instead of deploying and tuning standalone EMET policies.
- EMET's role as a separate mitigation toolkit is effectively absorbed into Windows, changing how enterprises standardize on Microsoft's own hardening guidance.
Second-order effects
- Attackers who relied on unmitigated memory-corruption paths now face per-app defenses by default, pushing exploit development toward bypassing the built-in mitigations rather than finding unguarded apps.
- Third-party endpoint vendors lose one differentiator as the OS ships native exploit defense — the same consolidation pressure that later showed up when Defender's Tamper Protection shipped enabled by default.
Third-order effects
- If the pattern holds, the operating system vendor becomes the default provider of baseline exploit protection, shrinking the market for standalone mitigation tools while concentrating risk in components like the Malware Protection Engine, which has already required two critical RCE patches (the second in April 2018).
- Security posture increasingly gets set at the platform-update cadence rather than by point-tool deployments, making Windows update adoption itself a security decision for enterprises.
The trend: Exploit defense is migrating from standalone tools like EMET into the operating system itself, with Microsoft shipping mitigations as built-in, per-app configuration at update cadence.