Scientists from the University of Birmingham and Durham University in the UK provedThe strongest Windows security measures can only be bypassed using software methods. The root of the problem is insufficient protection of the SPD chips on the memory modules, which are used by many large manufacturers.
Image credit: Andras Vas / unsplash.com
This attack scheme is called “download more RAM”. In carrying out this attack, a hypothetical attacker would abuse the fact that the SPD (Serial Presence Detection) configuration chip on the RAM module (which informs the PC of its characteristics) is not write-protected. Therefore, you can use software to make Windows “see” more memory than you actually have. The extra memory address appears in the system’s address space, acts as an alias for the real address, and opens a backdoor that allows you to bypass any access controls installed on the system and processor.
Researchers have shown that by exploiting this vulnerability, an attacker could:
- Run vulnerable drivers that have been used in known malware attacks;
- Disable antivirus and security software that continuously monitors security;
- Access isolated memory areas that Windows uses to protect its most critical components and data;
- Bypass group policy restrictions on corporate computers;
- Bypass game anti-cheat programs that use privileges at the core level.
Image credit: Kevin Ku/unsplash.com
The researchers developed a sample script that can be run and execute the entire attack chain with a single click: creating a memory address alias, restarting the computer, and disabling antivirus software. They found that Corsair, G.Skill and Adata all had at least one product line with a completely unsafe chip configuration, contrary to JEDEC recommendations. Together, these suppliers account for 55% of the high-performance consumer memory market and more than 70% of the gaming sector. Crucial, Kingston and HyperX modules, as well as some G.Skill series, only have partial write protection, which is not enough to prevent attacks.
The researchers showed that with this attack, data can be read and written to any area of system memory, even if access to those areas is prohibited by Windows security mechanisms. As a result, not only were virtualization security measures compromised, but so was the Hypervisor Enforced Code Integrity (HVCI) technology designed to protect Windows from attackers with administrator privileges. Microsoft has confirmed the vulnerability exists. This issue is assigned CVE-2026-23670 and is fixed in the April Windows security update. Only machines with Secure Boot disabled remain vulnerable. Corsair has added a new feature in the iCue app that allows you to enable write protection for published memory modules. For some modules from other manufacturers, the HwInfo utility provides similar options. In some cases, you can block writes to the chip via the BIOS – as a temporary solution.
If you find an error, select it with your mouse and press CTRL+ENTER.










