Researchers find Windows 11 can be hacked with no physical access with new attack - Neowin
DEALS
Software
Gaming
Reviews
Guides
Hands On
Specs Appeal
Opinion
Windows 11
Write for us?
Send news tip
-->
When Windows 11 was first released, one of the biggest talking points was OS system requirements, such as TPM and HVEC, that Microsoft reasoned were necessary to make Windows 11 the most secure Windows ever.
However, those security protections can apparently be bypassed using nothing more than software, with researchers demonstrating an attack that previously required physical access to the target machine.
The new findings come from security researchers at the University of Birmingham and Durham University, who presented their findings at the 2026 USENIX Security Symposium in Baltimore this week. Dubbed “Download More RAM,” the attack exploits an overlooked weakness in how some consumer memory modules report their configuration to a computer.
The problem lies in a configuration chip on certain DDR4 and DDR5 DIMMs that tells the system how much memory is installed. On affected modules, this chip lacks write protection, allowing software to modify the information it contains. This can then make Windows believe that the system has twice as much RAM as it actually does.
That sounds relatively harmless, but the resulting extra memory addresses can act as aliases for real memory locations. Therefore, this gives an attacker a way to read and modify memory that should otherwise be protected by Windows and the processor.
It is a little ironic that this news drops at a time Microsoft is quite actively working to improve memory performance, as that has been a major complaint.
The researchers used this technique to bypass several of Windows’ security measures, including Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus and EDR software, re-enable vulnerable drivers previously blocked because of their use in malware campaigns, compromise locked-down corporate systems, and bypass kernel-level game anti-cheat protections.
Interestingly and rather concerningly, the team also created a one-click script capable of chaining the attack together, including creating the memory aliases, rebooting the machine, and disabling antivirus without requiring further user interaction.
The researchers found that Corsair, G.Skill, and ADATA each ship at least one consumer memory product line with the configuration chip completely unprotected. These are major memory vendors, and so together, the companies are said to account for a large portion of the high-performance consumer (~55%) and gaming memory (~70%) markets.
The good news is that Microsoft was notified before the research became public and assigned the issue ID CVE-2026-23670. The Redmond giant has since issued mitigations in its April 2026 security updates. Thus, systems with Secure Boot enabled are protected against the attack in its current form.
Users are therefore advised to make sure Secure Boot is enabled and update to the latest (August 2026) Windows Patch Tuesday updates (Windows 10 / Windows 11) as they are cumulative in nature. Corsair has also added an option to its iCUE software to enable write protection on affected modules, while HWiNFO has added similar functionality for non-Corsair memory. Some motherboards additionally provide BIOS settings that can prevent writes to these configuration chips.
If you want to read more, you can check out this article on the official USENIX website.
Tags
Microsoft
University of birmingham
Durham university
Download more ram
Windows 11
Windows security
Windows 11 security
Vbs
Memory bug
Memory issue
Security vulnerability
Security flaw
Cve-2026-23670
Follow us onGoogle News
Add as a preferredsource on Google
Follow@NeowinFeed
Post
Like
Share
Share
Share
RSS
Report a problemwith this article
Related Stories
Get the Neowin newsletter
Subscribe
We'll send you a confirmation link. You can unsubscribe at any time.
🛍️ Shop on Amazon using our link:
shop at Amazon at no extra cost
☕️ Support us with a virtual coffee:
2.00 Dollars ($)<br>5.00 Dollars ($)<br>10.00 Dollars ($)<br>20.00 Dollars ($)<br>25.00 Dollars ($)<br>50.00 Dollars ($)<br>100.00 Dollars ($)
🏦 Or support us with a bank transfer
Community Activity
Refresh
Limitations of SteamOS?
in<br>PC Gaming
Upgrading an old NAS
in<br>Hardware Hangout
What are you listening to?
in<br>Wall of Sound
World AI issues
in<br>Artificial Intelligence (AI)
Best Video Footage of the Solar Eclipse in Spain on August 12 2026
in<br>Science News & Discussion
Cleaner finds 1991 Mars bar and compares to 2026 variant
in<br>General Discussion
Getting email to work with website host
in<br>Web Design & Development
AI Agents Enter Voting Machines and Delete Voters
in<br>Artificial Intelligence (AI)
The Mark Zuckerberg Manifesto.... in a nutshell
in<br>Artificial Intelligence (AI)
Is there...