Researchers find Windows 11 can be hacked with no physical access

stalkHN24x71 pts0 comments

Researchers find Windows 11 can be hacked with no physical access with new attack - Neowin

DEALS

Software

Gaming

Reviews

Guides

Hands On

Specs Appeal

Opinion

Windows 11

Write for us?

Send news tip

-->

When Windows 11 was first released, one of the biggest talking points was OS system requirements, such as TPM and HVEC, that Microsoft reasoned were necessary to make Windows 11 the most secure Windows ever.

However, those security protections can apparently be bypassed using nothing more than software, with researchers demonstrating an attack that previously required physical access to the target machine.

The new findings come from security researchers at the University of Birmingham and Durham University, who presented their findings at the 2026 USENIX Security Symposium in Baltimore this week. Dubbed “Download More RAM,” the attack exploits an overlooked weakness in how some consumer memory modules report their configuration to a computer.

The problem lies in a configuration chip on certain DDR4 and DDR5 DIMMs that tells the system how much memory is installed. On affected modules, this chip lacks write protection, allowing software to modify the information it contains. This can then make Windows believe that the system has twice as much RAM as it actually does.

That sounds relatively harmless, but the resulting extra memory addresses can act as aliases for real memory locations. Therefore, this gives an attacker a way to read and modify memory that should otherwise be protected by Windows and the processor.

It is a little ironic that this news drops at a time Microsoft is quite actively working to improve memory performance, as that has been a major complaint.

The researchers used this technique to bypass several of Windows’ security measures, including Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus and EDR software, re-enable vulnerable drivers previously blocked because of their use in malware campaigns, compromise locked-down corporate systems, and bypass kernel-level game anti-cheat protections.

Interestingly and rather concerningly, the team also created a one-click script capable of chaining the attack together, including creating the memory aliases, rebooting the machine, and disabling antivirus without requiring further user interaction.

The researchers found that Corsair, G.Skill, and ADATA each ship at least one consumer memory product line with the configuration chip completely unprotected. These are major memory vendors, and so together, the companies are said to account for a large portion of the high-performance consumer (~55%) and gaming memory (~70%) markets.

The good news is that Microsoft was notified before the research became public and assigned the issue ID CVE-2026-23670. The Redmond giant has since issued mitigations in its April 2026 security updates. Thus, systems with Secure Boot enabled are protected against the attack in its current form.

Users are therefore advised to make sure Secure Boot is enabled and update to the latest (August 2026) Windows Patch Tuesday updates (Windows 10 / Windows 11) as they are cumulative in nature. Corsair has also added an option to its iCUE software to enable write protection on affected modules, while HWiNFO has added similar functionality for non-Corsair memory. Some motherboards additionally provide BIOS settings that can prevent writes to these configuration chips.

If you want to read more, you can check out this article on the official USENIX website.

Tags

Microsoft

University of birmingham

Durham university

Download more ram

Windows 11

Windows security

Windows 11 security

Vbs

Memory bug

Memory issue

Security vulnerability

Security flaw

Cve-2026-23670

Follow us onGoogle News

Add as a preferredsource on Google

Follow@NeowinFeed

Post

Like

Share

Share

Share

RSS

Report a problemwith this article

Related Stories

Get the Neowin newsletter

Subscribe

We'll send you a confirmation link. You can unsubscribe at any time.

🛍️ Shop on Amazon using our link:

shop at Amazon at no extra cost

☕️ Support us with a virtual coffee:

2.00 Dollars ($)<br>5.00 Dollars ($)<br>10.00 Dollars ($)<br>20.00 Dollars ($)<br>25.00 Dollars ($)<br>50.00 Dollars ($)<br>100.00 Dollars ($)

🏦 Or support us with a bank transfer

Community Activity

Refresh

Limitations of SteamOS?

in<br>PC Gaming

Upgrading an old NAS

in<br>Hardware Hangout

What are you listening to?

in<br>Wall of Sound

World AI issues

in<br>Artificial Intelligence (AI)

Best Video Footage of the Solar Eclipse in Spain on August 12 2026

in<br>Science News & Discussion

Cleaner finds 1991 Mars bar and compares to 2026 variant

in<br>General Discussion

Getting email to work with website host

in<br>Web Design & Development

AI Agents Enter Voting Machines and Delete Voters

in<br>Artificial Intelligence (AI)

The Mark Zuckerberg Manifesto.... in a nutshell

in<br>Artificial Intelligence (AI)

Is there...

windows memory security dollars researchers attack

Related Articles