Windows 11 security vulnerability discovered in consumer RAM
Researchers from the University of Birmingham and the University of Durham have demonstrated a vulnerability that allows attackers to bypass Windows 11 security defenses without physical access to the device. The study, presented at the USENIX Security Symposium 2026, reveals that an attacker can dismantle core security protections using only software.
The vulnerability exploits a flaw in certain consumer RAM modules where the chip storing memory configuration information lacks write protection. By modifying this data, researchers were able to trick the system into believing it had approximately twice its actual memory capacity. This creates memory address aliases that allow an attacker to access protected memory regions that the operating system and processor are designed to isolate.
This technique enables the arbitrary reading and modification of memory, including areas that Windows considers inaccessible. The flaw directly impacts technologies intended to prevent attackers with administrative privileges from compromising the system kernel.
Entities
USENIX Security Symposium · University of Birmingham · University of Durham · Windows 11
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] An attacker can bypass Windows 11 security defenses using only software without physical access to the computer. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] By modifying configuration, researchers made the system believe it had approximately double its actual memory. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] Researchers from the University of Birmingham and the University of Durham conducted the study. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The technique allows for arbitrary reading and modification of memory that Windows considers inaccessible. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The study was presented at the USENIX Security Symposium 2026. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The attack exploits consumer RAM modules where the configuration chip may lack write protection. www.eldia.es · www.informacion.es · www.farodevigo.es