What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The “Windows subsystem” in this 2015 report was WoW64—the Windows compatibility layer that runs unmodified 32-bit applications on 64-bit Windows—not Windows Subsystem for Linux (WSL). Duo Security researchers described how the transition between 32-bit and 64-bit execution could be used to bypass certain EMET mitigations in a specific proof-of-concept setup. It was a historical mitigation limitation, not evidence of a current, generally exploitable flaw affecting every Windows system or application.

What WoW64 and EMET are

WoW64 lets 32-bit Windows programs run on 64-bit editions of Windows. EMET, short for Enhanced Mitigation Experience Toolkit, was Microsoft’s tool for applying exploit mitigations to applications. The 2015 report examined how those mitigations behaved when a 32-bit process ran through WoW64 and execution crossed into 64-bit code.

This distinction matters: the report was about application compatibility and process architecture on 64-bit Windows. It was not about Linux programs running inside Windows.

What the 2015 demonstration did

Duo Security researchers Darren Kemp and Mikhail Davidov published “WoW64 and So Can You: Bypassing EMET With a Single Instruction” on November 2, 2015. SecurityWeek reported that they modified an existing exploit for Adobe Flash Player CVE-2015-0311, a use-after-free vulnerability. They reproduced the bypass on 64-bit Windows 7 with Internet Explorer 10 and EMET 5.2 and 5.5 beta. Those operating system, browser, and EMET versions describe the reported demonstration; they do not establish that the same result applies to other configurations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The researchers’ central point was that WoW64 created a special case in EMET’s handling of processes. As SecurityWeek reported Duo’s explanation, “While EMET provides support for both 32 and 64-bit processes, as a limitation of its design, it does not explicitly handle the special case of WoW64 processes. This makes using a 64-bit ROP chain and secondary stage a relatively straightforward method for bypassing a significant number of EMET’s mitigations.”

Duo also said that 64-bit editions of EMET did not support the ROP-related mitigations, making the situation more complicated to address. The researchers described improving EMET to cover those limitations as a non-trivial effort. These are statements about EMET as discussed in the 2015 report, not current guidance from Microsoft.

What the finding does—and does not—mean

The report identified a weakness in mitigation coverage for the demonstrated WoW64 execution path. It did not show that EMET was ineffective in general. Duo told SecurityWeek that EMET remained largely effective at complicating exploitation in true 32-bit and 64-bit applications, often forcing attackers to work around mitigations case by case, and that most off-the-shelf exploits would fail against EMET protections.

Microsoft’s response, reproduced in SecurityWeek’s November 3, 2015 account, said the company continued researching mitigations for EMET and that deploying the toolkit helped make exploitation more difficult. The reviewed reporting does not establish whether Microsoft later remediated this precise WoW64/EMET limitation, nor does it establish EMET’s complete lifecycle status. Avoid treating the demonstration as a current vulnerability advisory or inferring present-day protection status from it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to read the 80 percent browser figure

SecurityWeek attributed to Duo a 2015 estimate that 80 percent of browsers were 32-bit processes running under WoW64; SC Media repeated the same figure. It is a period-specific estimate, not a current measurement of browser architecture or prevalence. Neither report supports using it as a present-day statistic.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

WoW64 is not Windows Subsystem for Linux

WSL is a separate Windows feature for running Linux environments and applications. Microsoft says WSL was announced at BUILD in 2016 and first shipped with the Windows 10 Anniversary Update. Microsoft’s account distinguishes WSL 1, based on a Pico process provider and lxcore.sys, from WSL 2, which uses the Linux kernel in a virtual machine. Those technologies are unrelated to the WoW64/EMET demonstration.

Other security coverage of WSL should not be conflated with the 2015 report. Check Point’s 2017 “Bashware” discussed visibility gaps for security products monitoring Linux programs run through WSL. SANS published Amanda Draeger’s “Looking for Linux: WSL Key Evidence” on December 11, 2019, about Windows logging and indicators relevant to WSL monitoring.

Microsoft’s later WSL announcements likewise concern a different technology. In November 2023, it described enterprise controls including Defender for Endpoint visibility into running WSL distributions, Intune settings for WSL access and configuration, and networking controls such as Hyper-V firewall support. At announcement, the Defender plug-in was in preview, while Intune management and networking features were described as generally available; availability and supported versions should be checked against current Microsoft documentation. In May 2025, Microsoft said WSL code had been open sourced, while some components remained in the Windows image and were not open sourced at that time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.