# Computer memory architecture security vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/computer-memory-architecture-security-vulnerabilities
> Updated: 2026-08-26T07:40:14.000Z. Sources: 4. Developments: 2.

Researchers have identified critical vulnerabilities in computer memory architecture that allow attackers to bypass hardware and software security boundaries. One method, referred to as the “Download More RAM” attack, exploits unprotected configuration chips on certain consumer RAM modules from manufacturers such as Corsair, G. Skill, and ADATA. By rewriting information reported to the system, software can trick an operating system like Windows into believing the computer has more RAM than it actually does.

This creates memory aliases that allow attackers to read or modify protected data without physical access to the device. The vulnerability enables the arbitrary reading and modification of memory, including areas that the operating system and processor are designed to isolate. This technique can be used to re-enable vulnerable drivers, compromise corporate systems, and evade kernel-level protections.

In addition to configuration chip exploits, research has detailed a DRAM scrambling attack that manipulates the memory controller’s address-translation logic. By altering how physical addresses map to DRAM cells, attackers can bypass hardware protections such as SEV, SGX, TDX, and TrustZone. Microsoft has addressed these issues via CVE-2026-23670, providing mitigations in security updates for Windows 10 and 11.

## Claims

- Researchers from the University of Birmingham and the University of Durham conducted the study. (corroborated by 3 sources)
- The study was presented at the USENIX Security Symposium 2026. (corroborated by 3 sources)
- An attacker can bypass Windows 11 security defenses using only software without physical access to the computer. (corroborated by 3 sources)
- The attack exploits consumer RAM modules where the configuration chip may lack write protection. (corroborated by 3 sources)
- By modifying configuration, researchers made the system believe it had approximately double its actual memory. (corroborated by 3 sources)
- The technique allows for arbitrary reading and modification of memory that Windows considers inaccessible. (corroborated by 3 sources)

## Timeline

### 2026-08-26: Windows 11 security vulnerability discovered in consumer RAM

Researchers have discovered a software-based vulnerability in Windows 11 that allows attackers to bypass core security protections by exploiting unprotected configuration chips in consumer RAM modules.

4 sources. https://clstr.news/cluster/windows-11-security-vulnerability-discovered-in-consumer-ram

### 2026-08-13: Memory controller vulnerabilities allow bypass of hardware security

New research reveals vulnerabilities in DRAM controllers and memory configuration chips that allow attackers to bypass Windows 11 defenses and hardware security boundaries like SGX and TrustZone.

3 sources. https://clstr.news/cluster/memory-controller-vulnerabilities-allow-bypass-of-hardware-security

---
Cite as: Computer memory architecture security vulnerabilities. CLSTR, https://clstr.news/situations/computer-memory-architecture-security-vulnerabilities
