Skip to Content
Join the Network with Us — Join Membership


Windows 11 Hit by Unusual Hardware Attack That Works Without Physical Access

August 25, 2026

Researchers from the University of Birmingham and Durham University have disclosed a serious hardware-based attack capable of bypassing key Windows 11 security protections, without ever needing physical access to the targeted computer. The findings were presented at the 2026 USENIX Security Symposium, showing how weaknesses in the configuration memory of certain consumer RAM modules can be exploited to undermine security mechanisms Windows relies on.

How the Attack Actually Works

The technique, dubbed "Download More RAM," takes advantage of inadequate write protection on a small configuration chip found in some DIMMs (Dual In-line Memory Modules), the component that tells a computer how much memory is installed. On affected modules, this configuration can be modified through software alone, because the chip isn't sufficiently protected against unauthorised writes.

By altering this configuration, researchers showed a system can be tricked into believing it has significantly more memory than it physically contains. That discrepancy exposes additional memory addresses that act as aliases for genuine memory locations, effectively giving an attacker a backdoor into memory that should normally be shielded by operating system and processor-level security controls.

What This Access Actually Enables

Once inside, the researchers demonstrated the technique could re-enable hundreds of known-vulnerable drivers that had previously been blocked specifically because they'd been abused in malware and ransomware campaigns.

It doesn't stop there. The same memory-aliasing trick could also disable antivirus and Endpoint Detection and Response (EDR) software, the tools that continuously monitor systems for suspicious activity and are usually the first line of defence against exactly this kind of attack. The researchers further showed it could compromise Microsoft's Virtualization-based Security (VBS), including access to memory enclaves designed to isolate sensitive data, and even undermine Hypervisor-Enforced Code Integrity (HVCI), a protection specifically built to guard Windows even when an attacker already has administrator-level privileges.

A One-Click Attack, No User Interaction Required

Perhaps most concerning: the research team built a one-click script capable of automating the entire attack chain, memory aliasing, system reboot, and disabling antivirus protections, without requiring any further user interaction. That raises real concerns about the potential for automated, large-scale exploitation if the technique were to spread beyond controlled research conditions.

Which Memory Modules Are Affected

The team surveyed popular consumer DDR4 and DDR5 memory modules and found that at least one product line each from Corsair, G.Skill, and ADATA had configuration chips without complete write protection. Together, these three manufacturers account for roughly 55% of the high-performance consumer memory market and more than 70% of the gaming segment, a significant chunk of the market by any measure.

On the other hand, modules from Crucial, Kingston, and HyperX, along with some G.Skill product lines, were found to use partial write protection sufficient to block the demonstrated attack.

Microsoft's Response

Following coordinated disclosure procedures, the researchers informed affected vendors before going public. Microsoft acknowledged the vulnerability, assigned it CVE-2026-23670, and rolled out mitigations through its April 2026 security updates. Windows systems with Secure Boot enabled are currently protected against this specific form of attack, but systems running without Secure Boot may still be vulnerable. Researchers are advising users and organisations to confirm Secure Boot is switched on and apply the relevant Microsoft updates without delay.

What Memory Makers Are Doing

Corsair has since added functionality to its iCUE software allowing users to enable write protection on compatible memory modules after installation, a hardware-level mitigation that closes the gap directly at the source. The HWiNFO utility has incorporated similar functionality for compatible modules from other manufacturers, and some motherboard makers also offer BIOS settings that can block write operations to memory configuration chips altogether.

As one University of Birmingham researcher put it, strong operating system security ultimately depends on the integrity of the lower-level components beneath it, if an attacker can compromise that foundational layer, everything built on top of it becomes vulnerable too. The overall lesson: protecting a Windows system properly now requires more than software updates and antivirus tools alone. Organisations using potentially affected hardware should verify Secure Boot status, install Microsoft's latest security updates, and enable hardware-level write protection wherever it's supported.

FAQs

Q1. Does this attack require physical access to the computer?

No. That's what makes it particularly concerning, the researchers demonstrated it can be executed entirely through software, without needing to physically touch the targeted machine.

Q2. Which memory brands are affected?

At least one product line each from Corsair, G.Skill, and ADATA was found to lack complete write protection. Crucial, Kingston, HyperX, and some G.Skill lines had sufficient partial protection to block the attack.

Q3. How can users protect themselves?

Verify that Secure Boot is enabled, install Microsoft's April 2026 security updates (which address CVE-2026-23670), and enable hardware-level write protection where supported by the memory manufacturer's software or BIOS.

Q4. What security protections can this attack bypass?

Antivirus and EDR software, Microsoft's Virtualization-based Security (VBS), and Hypervisor-Enforced Code Integrity (HVCI), even in cases where an attacker already has administrator-level privileges.

in News
Share this post
Archive