Researchers were able to read and modify any memory on the system, including memory that Windows guarantees is off-limits even to the operating system itself. This breaks not only VBS, but also Hypervisor Enforced Code Integrity (HVCI) - the technologies Microsoft designed to protect Windows even against attackers with administrator rights.
Dr Marius Muench, from the University of Birmingham, said: “The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk.
“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to."
Coordinated disclosure
The work follows coordinated disclosure practice: all affected vendors were notified with full technical details well ahead of publication.
Microsoft acknowledged the team’s findings, assigned CVE-2026-23670, and issued mitigations in its April 2026 security updates. Windows machines running with SecureBoot enabled are protected against the attack in its current form. Machines without SecureBoot remain vulnerable, and the research team advises users to ensure that SecureBoot is enabled.
Corsair has added a feature to its iCue tooling that lets owners retroactively enable write protection on their memory modules, closing the hole at the hardware level. The free tool HWinfo has also adopted this functionality, providing mitigation for non-Corsair models. Some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.