Birmingham.Ac.Uk
New RAM Attack Bypasses Windows Security Without Physical Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers from the University of Birmingham and Durham University have demonstrated a new attack method, named 'Download More RAM', that allows attackers to bypass Windows 11's Virtualisation-Based Security (VBS) without needing physical access to the machine. This software-only memory aliasing attack exploits vulnerabilities in consumer memory modules, specifically targeting unprotected configuration chips in certain DDR4 and DDR5 DIMMs from manufacturers like Corsair, G.Skill, and ADATA. The attack enables arbitrary memory read/write, compromising the operating system's security guarantees, including Windows Defender and anti-virus software. Microsoft has assigned CVE-2026-23670 to this vulnerability and issued a partial patch. The attack's potential for automated, large-scale exploitation raises significant security concerns for millions of users relying on affected memory modules. The research was presented at the 2026 USENIX Security Symposium.
Key Points: • The 'Download More RAM' attack bypasses Windows 11 security without physical access. • Affected memory modules from Corsair, G.Skill, and ADATA lack write protection on configuration chips. • Microsoft has issued a partial patch for CVE-2026-23670 related to this vulnerability.