Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 4 sources · 13 days · First seen · Last updated
Computer memory architecture security vulnerabilities
Overview
Researchers have identified critical vulnerabilities in computer memory architecture that allow attackers to bypass hardware and software security boundaries. One method, referred to as the “Download More RAM” attack, exploits unprotected configuration chips on certain consumer RAM modules from manufacturers such as Corsair, G. Skill, and ADATA. By rewriting information reported to the system, software can trick an operating system like Windows into believing the computer has more RAM than it actually does.
This creates memory aliases that allow attackers to read or modify protected data without physical access to the device. The vulnerability enables the arbitrary reading and modification of memory, including areas that the operating system and processor are designed to isolate. This technique can be used to re-enable vulnerable drivers, compromise corporate systems, and evade kernel-level protections.
In addition to configuration chip exploits, research has detailed a DRAM scrambling attack that manipulates the memory controller’s address-translation logic. By altering how physical addresses map to DRAM cells, attackers can bypass hardware protections such as SEV, SGX, TDX, and TrustZone. Microsoft has addressed these issues via CVE-2026-23670, providing mitigations in security updates for Windows 10 and 11.
Entities
University of Birmingham · University of Durham · Christopher Domas · USENIX Security Symposium · Microsoft
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Researchers from the University of Birmingham and the University of Durham conducted the study. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The study was presented at the USENIX Security Symposium 2026. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] An attacker can bypass Windows 11 security defenses using only software without physical access to the computer. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The attack exploits consumer RAM modules where the configuration chip may lack write protection. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] By modifying configuration, researchers made the system believe it had approximately double its actual memory. www.eldia.es · www.informacion.es · www.farodevigo.es
- [● 3 SOURCES] The technique allows for arbitrary reading and modification of memory that Windows considers inaccessible. www.eldia.es · www.informacion.es · www.farodevigo.es
Timeline
-
3 days ago
[TECHNOLOGY] 4 sourcesWindows 11 security vulnerability discovered in consumer RAMResearchers have discovered a software-based vulnerability in Windows 11 that allows attackers to bypass core security protections by exploiting unprotected configuration chips in consumer RAM modules.
-
15 days ago
[TECHNOLOGY] 3 sourcesMemory controller vulnerabilities allow bypass of hardware securityNew research reveals vulnerabilities in DRAM controllers and memory configuration chips that allow attackers to bypass Windows 11 defenses and hardware security boundaries like SGX and TrustZone.
Sources
ocio.diariodemallorca.es · ocio.diarioinformacion.com · ocio.farodevigo.es · startup.mandiner.hu