Windows 11 new attack on secure Windows (with TPM)

When Windows 11 was first released, one of the biggest topics of discussion was the operating system requirements, such as TPM and HVEC, which Microsoft considered necessary to make Windows 11 the most secure Windows ever released.Microsoft Windows 11

However, these security protections can apparently be bypassed using software alone, with the researchers demonstrating an attack that previously required physical access to the target machine.

See more articles from iGuRu.gr when you search for news on Google.

The new findings come from security researchers from the University of Birmingham and Durham University, who presented their findings at the 2026 USENIX Security Symposium in Baltimore this week. Dubbed “Download More RAM,” the attack exploits a weakness in the way some consumer memory modules report their configuration to a computer.

The issue lies in a configuration chip in some DDR4 and DDR5 DIMMs that tells the system how much memory is installed. In the affected units, this chip is not write-protected, allowing software to modify the information it contains. This can then trick Windows into thinking the system has twice as much RAM as it actually has.

This may sound harmless, but the resulting extra memory addresses can act as “aliases” for actual memory locations, giving an attacker a way to read and modify memory that should be protected by Windows and the processor.

The researchers used this technique to bypass many of Windows' security measures, including Virtualization-Based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus software and were able to re-enable vulnerable drivers that had been blocked due to their use in malware campaigns.

The team also created a script that, with a single click, is capable of carrying out a parallel attack, creating memory aliases, rebooting the machine, and disabling the antivirus without requiring further user interaction.

The researchers found that Corsair, G.Skill, and ADATA have at least one memory product line that has the configuration chip completely unprotected. These are major memory suppliers and represent a large portion of the consumer high-performance memory (~55%) and gaming memory (~70%) markets.

It is therefore recommended that you have Secure Boot enabled and install the latest (August 2026) Windows Patch Tuesday updates (Windows 10 / Windows 11), as they are cumulative. Corsair has also added an option in its iCUE software to enable write protection on affected drives, while HWiNFO has added similar functionality for non-Corsair memory. Some motherboards provide additional BIOS settings that can prevent writes to these configuration chips.

You can read more on the official USENIX website.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).