Skip to content
Breaking:

Microsoft Patches Windows Flaw That Allowed Script-Based Antivirus Disabling via RAM Exploits

Researchers at the 2026 USENIX Security Symposium demonstrated how unsecured memory modules enabled a single-click bypass of Windows core defenses.

By The Company Wire4 min read
Share
Microsoft — Microsoft Patches Windows Flaw That Allowed Script-Based Antivirus Disabling via RAM Exploits
Microsoft — Microsoft Patches Windows Flaw That Allowed Script-Based Antivirus Disabling via RAM Exploits. Photo: web.

Microsoft Corp. has patched a Windows security vulnerability that enabled threat actors to bypass fundamental operating system defenses, terminate endpoint antivirus software, and gain administrative control over target computers through automated script execution.

Discovered by academic researchers from the University of Birmingham and Durham University, the security flaw was presented at the 2026 USENIX Security Symposium under the project name "Download more RAM." The attack vector targets specific consumer DDR4 and DDR5 memory modules whose configuration control chips permit software to modify the memory parameters reported to system motherboards.

By instructing a memory chip to report double its physical capacity, the researchers demonstrated that artificial memory addresses could be generated. These phantom memory locations functioned as aliases for system memory areas strictly reserved for hardware-level and operating system security controls. Consequently, the method allowed researchers to circumvent Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI), two core defensive systems introduced in Windows 10 to isolate critical functions and restrict kernel access to authenticated code.

The vulnerability allowed researchers to disable endpoint detection and response (EDR) agents, strip away default antivirus defenses, reinstall outdated and exploitable hardware drivers, bypass anti-cheat mechanisms, and compromise restricted corporate workstations. Unlike prior hardware-based memory exploits that required physical access and specialized tools, this technique can be packaged into a simple executable script that automates address spoofing, triggers a system reboot, and dismantles OS protections, as first reported by TechRadar Pro.

"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees," said Professor Tom Chothia of the University of Birmingham. "Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."

The research team found that major memory vendors including Corsair, G.Skill, and ADATA shipped consumer RAM lines without write protections on configuration chips. These manufacturers account for roughly 55 percent of the high-performance consumer RAM sector and 70 percent of the gaming market, though not every product line was affected. Conversely, hardware modules from Crucial, Kingston, and HyperX incorporated sufficient write safeguards to block the exploit.

The flaw, cataloged as CVE-2026-23670, is documented in the National Vulnerability Database as an untrusted pointer dereference within the Windows VBS Enclave that permits local privilege escalation and security bypasses. Microsoft assigned the flaw a CVSS severity rating of 5.7 out of 10 and issued a fix as part of its April 2026 Patch Tuesday cumulative update. Devices operating with Secure Boot activated are protected against the vulnerability.

Hardware and utility developers have also issued interim safeguards. Corsair updated its iCue management software to allow users to apply write protections to vulnerable RAM hardware retroactively, while third-party utility HWinfo made similar functions available for other brands. Additionally, select motherboard manufacturers have exposed BIOS settings to block unauthorized software writes to memory configuration microcontrollers.

"The 'Download More RAM' attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk," said Dr. Marius Muench of the University of Birmingham. "Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself—on a lot of the memory people actually buy, it doesn't have to."

Sources

  1. TechRadar Pro

Company: Microsoft

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.