New RAM Attack Bypasses Windows Security Without Physical Access

New RAM Attack Bypasses Windows Security Without Physical Access

First seen 13 Aug 2026, 16:49 UTC Birmingham.Ac.Ukwww.usenix.org 73% similarity 67.5

Article Content

Browse articles
ThreatCluster

Researchers from the University of Birmingham and Durham University have demonstrated a new attack method, named 'Download More RAM', that allows attackers to bypass Windows 11's Virtualisation-Based Security (VBS) without needing physical access to the machine. This software-only memory aliasing attack exploits vulnerabilities in consumer memory modules, specifically targeting unprotected configuration chips in certain DDR4 and DDR5 DIMMs from manufacturers like Corsair, G.Skill, and ADATA. The attack enables arbitrary memory read/write, compromising the operating system's security guarantees, including Windows Defender and anti-virus software. Microsoft has assigned CVE-2026-23670 to this vulnerability and issued a partial patch. The attack's potential for automated, large-scale exploitation raises significant security concerns for millions of users relying on affected memory modules. The research was presented at the 2026 USENIX Security Symposium.

Key Points: • The 'Download More RAM' attack bypasses Windows 11 security without physical access. • Affected memory modules from Corsair, G.Skill, and ADATA lack write protection on configuration chips. • Microsoft has issued a partial patch for CVE-2026-23670 related to this vulnerability.

ThreatCluster AI How this analysis works

Timeline

2026-04-14
CVE-2026-23670 published
Microsoft assigned CVE-2026-23670 to the vulnerability exploited by the Download More RAM attack.
www.usenix.org
2026-08-13
Research findings presented at USENIX Security Symposium
Researchers revealed the Download More RAM attack, demonstrating its ability to compromise Windows security without physical access.
Birmingham.Ac.Uk
Recent
Microsoft issues partial patch
Microsoft released a patch to mitigate the vulnerabilities associated with CVE-2026-23670, though it is only a partial fix.
www.usenix.org

Community

Browse all →

Tracked Entities in This Story