Security1 publisher3 min readPublished
Windows 11's secure kernel trusts a RAM chip that never checks who is writing to it
Birmingham and Durham researchers rewrote a DIMM's configuration chip in software to alias in-use memory, then reached into VBS enclaves, revived blocklisted drivers and killed EDR.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Researchers from the University of Birmingham and Durham University found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine.
- The attack assumes the attacker has already gained privileged access to the system.
- The attack, named "Download More RAM", targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), which stores information about the memory module including its capacity and configuration.
- On several consumer memory modules, nothing stops software from rewriting critical parts of that configuration chip.
- An attacker who overwrites that information can make a machine believe it has more memory than it does; the extra addresses do not correspond to new physical RAM, and some alias memory already in use, allowing accesses that bypass the isolation Windows and the processor normally enforce.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Researchers at the University of Birmingham and Durham University have shown that some of the toughest protections in Windows 11 can be knocked down without opening or physically modifying the target machine, by rewriting the small configuration chip that sits on the RAM stick [1][3]. The attack starts from privileged access [2], which is exactly the position that Virtualisation-based Security and Hypervisor-Enforced Code Integrity were built to survive [13][22].
The mechanism is unglamorous. Every DIMM carries a configuration chip holding information about the module, including its capacity and configuration [3]. On several consumer memory modules, the researchers report, nothing stops software from rewriting critical parts of that chip [4]. Overwrite it and the machine believes it has more memory than it does; the extra addresses do not correspond to new physical RAM, and some of them alias memory already in use, allowing accesses that bypass the isolation Windows and the processor normally enforce [5]. "Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script," said Tom Chothia, professor of cyber security at Birmingham [6].
What the aliasing buys is broad. The team says it reached parts of the system Windows is built to keep off-limits, including memory the operating system itself is not supposed to touch [7]. From there they turned hundreds of blocklisted drivers with known vulnerabilities back on, including drivers previously associated with malware and ransomware [8]; killed antivirus and EDR software [9]; read data out of VBS enclaves that was meant to stay isolated [10]; got past corporate device-management rules including group-policy restrictions of the kind used on enterprise and university-managed machines [11]; and slipped past kernel-level anti-cheat in games [12]. They also built a script that chains the steps together on its own, aliasing memory, rebooting and shutting off antivirus with no further clicks or prompts from the user [15].
The framing from lead author Sam Collins is the part worth keeping: "In this scenario Microsoft VBS blindly trusted the shaky ground it stood on" [14]. Marius Muench, assistant professor at Birmingham, put the same point in terms of assumptions, saying the promise that an administrator cannot touch the secure kernel "rests on the assumption that your memory is telling the truth about itself" [16]. There is no authentication step between software and the module's description of itself, so the integrity check that the higher layers depend on is not a weak check; it is absent [4][5].
Exposure is a procurement question, not a settings question. A survey of popular DDR4 and DDR5 modules found several vendors shipping at least one product line with the configuration chip left without write protection, which the researchers say runs contrary to JEDEC guidance [17]. They estimate those lines account for more than half of the high-performance consumer memory market and over 70 percent of the gaming segment [18]. Other modules use partial write protection, and that was enough to block the attack [19]. The flaw sits at the module level rather than with a single manufacturer, so buyers need the write-protection status of their specific model rather than a brand-level assurance [20][23].
Watch for vendors moving affected lines to write-protected configuration chips, and for anything from Microsoft on whether VBS and HVCI will validate the memory topology they inherit rather than trusting it [13][17]. Disclosure was coordinated, with affected vendors given technical details before publication [21], so the near-term signal is which SKUs change and which quietly do not.