Skip to content

Glossary

Control Flow Guard (CFG)

A Windows forward-edge mitigation that checks every indirect call against a bitmap of valid targets, blocking jumps into the middle of functions or into data.

Control Flow Guard (CFG) is a Windows control-flow-integrity mitigation for the forward edge. Built with /guard:cf, the compiler and OS maintain a bitmap of valid indirect-call targets (function entry points), and every indirect call is checked against it before dispatch. A ROP- or call-oriented chain that targets the middle of a function, or attacker data, is not a valid target and is blocked.

CFG is coarse-grained — it allows any registered function entry, so valid-but-dangerous targets can remain reachable — and it does not protect returns, which is why it is paired with hardware CET's shadow stack for the backward edge. It is the Windows counterpart of CFI. See Windows flow-integrity mitigations.