Researchers from the University of Birmingham and Durham University disclosed "Download More RAM," a software-only attack that rewrites writable SPD EEPROM data on certain DDR4 and DDR5 DIMMs over SMBus/I2C, causing memory to falsely report more capacity and creating aliased physical memory regions on Windows 11 systems. With local administrator privileges, an attacker can use the aliased region to read and write protected memory, patch Secure Kernel Code Integrity, and bypass defenses including VBS, HVCI, DSE, and PatchGuard; the technique was also shown disabling Microsoft Defender and Sophos Intercept X, modifying VBS enclaves, bypassing anti-cheat protections, and enabling blocked vulnerable drivers to load.
Microsoft tracked the issue as CVE-2026-23670 and shipped mitigations in its April 2026 security updates, including blocking the demonstrated stabilization method, disabling the removememory boot parameter on Secure Boot systems, and extending VBS protections to some systems without Secure Boot. The researchers said the mitigation is partial and that systems lacking Secure Boot may remain exposed if alternative stabilization methods are found. The affected hardware identified in the research includes consumer DIMM lines from Corsair, G.Skill, and ADATA with SPD write protection disabled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers from the University of Birmingham and Durham University presented the 'Download More RAM' attack at the 35th USENIX Security Symposium in Baltimore. They described it as a software-only memory aliasing attack against certain DDR4 and DDR5 DIMMs that can bypass Windows protections including VBS and HVCI.
Microsoft released mitigations in its April 2026 security update for CVE-2026-23670, including blocking the demonstrated use of the removememory boot parameter on Secure Boot systems. The mitigation was described as partial, with systems without Secure Boot still vulnerable according to the research coverage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.