New “Download More RAM” Attack Can Bypass Windows Security
The Download More RAM attack can let hackers bypass major Windows security protections using software alone, without needing physical access to the PC.
Security researchers from the University of Birmingham and Durham University disclosed the technique at the 2026 USENIX Security Symposium. Microsoft tracks the vulnerability as CVE-2026-23670.
Download More RAM attack targets DDR4 and DDR5 memory
The attack targets configuration chips found on some DDR4 and DDR5 DIMMs. These chips tell the system how much memory the PC has installed.
On vulnerable modules, the configuration chip lacks write protection. Attackers can modify its data and make Windows believe the system has twice as much RAM as it actually does.
That creates fake memory aliases pointing to real physical memory locations. Attackers can then use those aliases to read or modify protected memory that Windows security mechanisms would normally isolate.
VBS and HVCI can be bypassed
Researchers demonstrated that Download More RAM can bypass Virtualization-based Security and Hypervisor-Enforced Code Integrity.
The attack could also disable antivirus and EDR software, restore access to vulnerable drivers blocked by Windows, compromise locked-down corporate PCs, and bypass kernel-level anti-cheat systems used by games.
Researchers also created a one-click script capable of setting up the memory aliases, rebooting the computer, and disabling antivirus without requiring further user interaction.
At least one consumer memory product line from Corsair, G.Skill, and ADATA was found vulnerable during the research.
Microsoft patched the attack in April
Microsoft received details about the vulnerability before its public disclosure and introduced mitigations with the April 2026 Windows security updates.
According to the researchers, PCs with Secure Boot enabled remain protected against the attack in its currently demonstrated form.
Users should enable Secure Boot and install current Windows cumulative updates. Microsoft’s latest August Patch Tuesday release fixed around 400 security flaws.
Corsair has also added an iCUE option that enables write protection on affected memory modules. HWiNFO provides similar protection for non-Corsair RAM, while some motherboards include BIOS settings that can block software from writing to memory configuration chips.
In other security news, attackers are already using a critical SharePoint exploit, while security experts have warned that hackers could exploit Microsoft’s Entra passkey rollout.
Via Neowin
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages