Download More RAM Attack Bypasses Windows 11 Security Defenses

Download More RAM Attack Bypasses Windows 11 Security Defenses

First seen 13 Aug 2026, 16:49 UTC Birmingham.Ac.UkFeeds.4Sysopswww.usenix.orgCybersecuritynewsGbhackers+4 84% similarity 72.5

Article Content

Browse articles
ThreatCluster

Researchers have identified a new attack, termed 'Download More RAM', that allows attackers to bypass Windows 11's Virtualization-Based Security (VBS) and disable Microsoft Defender without physical access to the target machine. This attack exploits vulnerabilities in certain consumer DDR4 and DDR5 memory modules, specifically targeting the unprotected Serial Presence Detect (SPD) data. The attack enables arbitrary memory read/write operations, compromising the operating system and its security features. Microsoft has acknowledged the issue as CVE-2026-23670 and released a partial mitigation in April 2026. The research was presented at the 2026 USENIX Security Symposium, highlighting a significant flaw in trust assumptions surrounding Windows security. The attack can be executed using a simple script, making it suitable for automated, large-scale exploitation. Major manufacturers like Corsair, G.Skill, and ADATA have been identified as having vulnerable products, affecting a significant portion of the high-performance memory market.

Key Points: • The 'Download More RAM' attack bypasses Windows 11 security without physical access. • CVE-2026-23670 was assigned to this vulnerability, with a partial patch released in April 2026. • Affected memory modules from Corsair, G.Skill, and ADATA account for over 55% of the high-performance market.

ThreatCluster AI How this analysis works

Timeline

2026-04-14
CVE-2026-23670 published
Microsoft acknowledged the vulnerability allowing bypass of Windows security features and issued a partial patch.
Cybersecuritynews
2026-08-12
Research presented at USENIX Security Symposium
Researchers from the University of Birmingham revealed the 'Download More RAM' attack, demonstrating its impact on Windows security.
Birmingham.Ac.Uk
2026-08-14
Public awareness of the attack grows
Multiple cybersecurity outlets report on the 'Download More RAM' attack and its implications for Windows security.
Feeds.4Sysops

Community

Browse all →