Interesting Article you can download the PDF for more info from the link
Sam Collins, Tom Chothia, William Burgess, and Marius Muench, The University of Birmingham; David Oswald, Durham University
The new findings come from security researchers at the University of Birmingham and Durham University, who presented their findings at the 2026 USENIX Security Symposium in Baltimore this week. Dubbed “Download More RAM,” the attack exploits an overlooked weakness in how some consumer memory modules report their configuration to a computer.
The problem lies in a configuration chip on certain DDR4 and DDR5 DIMMs that tells the system how much memory is installed. On affected modules, this chip lacks write protection, allowing software to modify the information it contains. This can then make Windows believe that the system has twice as much RAM as it actually does.
That sounds relatively harmless, but the resulting extra memory addresses can act as aliases for real memory locations. Therefore, this gives an attacker a way to read and modify memory that should otherwise be protected by Windows and the processor.
It is a little ironic that this news drops at a time Microsoft is quite actively working to improve memory performance, as that has been a major complaint.
The researchers used this technique to bypass several of Windows’ security measures, including Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus and EDR software, re-enable vulnerable drivers previously blocked because of their use in malware campaigns, compromise locked-down corporate systems, and bypass kernel-level game anti-cheat protections.
Interestingly and rather concerningly, the team also created a one-click script capable of chaining the attack together, including creating the memory aliases, rebooting the machine, and disabling antivirus without requiring further user interaction.
The researchers found that Corsair, G.Skill, and ADATA each ship at least one consumer memory product line with the configuration chip completely unprotected. These are major memory vendors, and so together, the companies are said to account for a large portion of the high-performance consumer (~55%) and gaming memory (~70%) markets.
The good news is that Microsoft was notified before the research became public and assigned the issue ID CVE-2026-23670. The Redmond giant has since issued mitigations in its April 2026 security updates. Thus, systems with Secure Boot enabled are protected against the attack in its current form.
Users are therefore advised to make sure Secure Boot is enabled and update to the latest (August 2026) Windows Patch Tuesday updates (Windows 10 / Windows 11) as they are cumulative in nature. Corsair has also added an option to its iCUE software to enable write protection on affected modules, while HWiNFO has added similar functionality for non-Corsair memory. Some motherboards additionally provide BIOS settings that can prevent writes to these configuration chips.
Sam Collins, Tom Chothia, William Burgess, and Marius Muench, The University of Birmingham; David Oswald, Durham University
The new findings come from security researchers at the University of Birmingham and Durham University, who presented their findings at the 2026 USENIX Security Symposium in Baltimore this week. Dubbed “Download More RAM,” the attack exploits an overlooked weakness in how some consumer memory modules report their configuration to a computer.
The problem lies in a configuration chip on certain DDR4 and DDR5 DIMMs that tells the system how much memory is installed. On affected modules, this chip lacks write protection, allowing software to modify the information it contains. This can then make Windows believe that the system has twice as much RAM as it actually does.
That sounds relatively harmless, but the resulting extra memory addresses can act as aliases for real memory locations. Therefore, this gives an attacker a way to read and modify memory that should otherwise be protected by Windows and the processor.
It is a little ironic that this news drops at a time Microsoft is quite actively working to improve memory performance, as that has been a major complaint.
The researchers used this technique to bypass several of Windows’ security measures, including Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus and EDR software, re-enable vulnerable drivers previously blocked because of their use in malware campaigns, compromise locked-down corporate systems, and bypass kernel-level game anti-cheat protections.
Interestingly and rather concerningly, the team also created a one-click script capable of chaining the attack together, including creating the memory aliases, rebooting the machine, and disabling antivirus without requiring further user interaction.
The researchers found that Corsair, G.Skill, and ADATA each ship at least one consumer memory product line with the configuration chip completely unprotected. These are major memory vendors, and so together, the companies are said to account for a large portion of the high-performance consumer (~55%) and gaming memory (~70%) markets.
The good news is that Microsoft was notified before the research became public and assigned the issue ID CVE-2026-23670. The Redmond giant has since issued mitigations in its April 2026 security updates. Thus, systems with Secure Boot enabled are protected against the attack in its current form.
Users are therefore advised to make sure Secure Boot is enabled and update to the latest (August 2026) Windows Patch Tuesday updates (Windows 10 / Windows 11) as they are cumulative in nature. Corsair has also added an option to its iCUE software to enable write protection on affected modules, while HWiNFO has added similar functionality for non-Corsair memory. Some motherboards additionally provide BIOS settings that can prevent writes to these configuration chips.
My Computer
At a glance
Windows 11 ProIntel Core i9 12900KFCorsair 64GB DDR5 Vengeance C40 5200MhzASUS GeForce RTX 3090 ROG Strix OC 24GB
- OS
- Windows 11 Pro
- Computer type
- PC/Desktop
- Manufacturer/Model
- Custom Build
- CPU
- Intel Core i9 12900KF
- Motherboard
- ASUS ROG Maximus Z690 Hero
- Memory
- Corsair 64GB DDR5 Vengeance C40 5200Mhz
- Graphics Card(s)
- ASUS GeForce RTX 3090 ROG Strix OC 24GB
- Sound Card
- OnBoard
- Monitor(s) Displays
- Acer Predator XB323UGP 32" QHD G-SYNC-C 144Hz 1MS IPS LED
- Screen Resolution
- 2560 x 1440
- Hard Drives
- 1x Samsung 980 Pro Series Gen4 250GB M.2 NVMe
1x Samsung 980 Pro Series Gen4 500GB M.2 NVMe
2x Samsung 980 Pro Series Gen4 2TB M.2 NVMe
- PSU
- Corsair AX1200i 1200W 80PLUS Titanium Modular
- Case
- Corsair 4000D Black Case w/ Tempered Glass Side Panel
- Cooling
- Noctua NH-U12A Chromax Black CPU Cooler, 4x Noctua 120mm Fans
- Keyboard
- Logitech MK545
- Mouse
- Logitech MX Master 3
- Internet Speed
- Fixed Wireless 150mbps/75mbps
- Browser
- Firefox
- Antivirus
- Kaspersky
- Other Info
- Thrustmaster TS-PC RACER
Fanatec CSL Elite Pedals with the Load Cell Kit
Yamaha Amp with Bose Speakers







