Security1 distinct publisher3 min readUpdated
Birmingham and Durham researchers rewrote a DIMM's configuration chip in software to alias in-use memory, then reached into VBS enclaves, revived blocklisted drivers and killed EDR.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Researchers at the University of Birmingham and Durham University have shown that some of the toughest protections in Windows 11 can be knocked down without opening or physically modifying the target machine, by rewriting the small configuration chip that sits on the RAM stick [1][3]. The attack starts from privileged access [2], which is exactly the position that Virtualisation-based Security and Hypervisor-Enforced Code Integrity were built to survive [13][22].
The mechanism is unglamorous. Every DIMM carries a configuration chip holding information about the module, including its capacity and configuration [3]. On several consumer memory modules, the researchers report, nothing stops software from rewriting critical parts of that chip [4]. Overwrite it and the machine believes it has more memory than it does; the extra addresses do not correspond to new physical RAM, and some of them alias memory already in use, allowing accesses that bypass the isolation Windows and the processor normally enforce [5]. "Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script," said Tom Chothia, professor of cyber security at Birmingham [6].
What the aliasing buys is broad. The team says it reached parts of the system Windows is built to keep off-limits, including memory the operating system itself is not supposed to touch [7]. From there they turned hundreds of blocklisted drivers with known vulnerabilities back on, including drivers previously associated with malware and ransomware [8]; killed antivirus and EDR software [9]; read data out of VBS enclaves that was meant to stay isolated [10]; got past corporate device-management rules including group-policy restrictions of the kind used on enterprise and university-managed machines [11]; and slipped past kernel-level anti-cheat in games [12]. They also built a script that chains the steps together on its own, aliasing memory, rebooting and shutting off antivirus with no further clicks or prompts from the user [15].
The framing from lead author Sam Collins is the part worth keeping: "In this scenario Microsoft VBS blindly trusted the shaky ground it stood on" [14]. Marius Muench, assistant professor at Birmingham, put the same point in terms of assumptions, saying the promise that an administrator cannot touch the secure kernel "rests on the assumption that your memory is telling the truth about itself" [16]. There is no authentication step between software and the module's description of itself, so the integrity check that the higher layers depend on is not a weak check; it is absent [4][5].
Exposure is a procurement question, not a settings question. A survey of popular DDR4 and DDR5 modules found several vendors shipping at least one product line with the configuration chip left without write protection, which the researchers say runs contrary to JEDEC guidance [17]. They estimate those lines account for more than half of the high-performance consumer memory market and over 70 percent of the gaming segment [18]. Other modules use partial write protection, and that was enough to block the attack [19]. The flaw sits at the module level rather than with a single manufacturer, so buyers need the write-protection status of their specific model rather than a brand-level assurance [20][23].
Watch for vendors moving affected lines to write-protected configuration chips, and for anything from Microsoft on whether VBS and HVCI will validate the memory topology they inherit rather than trusting it [13][17]. Disclosure was coordinated, with affected vendors given technical details before publication [21], so the near-term signal is which SKUs change and which quietly do not.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Researchers from the University of Birmingham and Durham University found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine.
The attack assumes the attacker has already gained privileged access to the system.
"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees... Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."
"Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself. On a lot of the memory people buy, it doesn't have to."
An attacker who overwrites that information can make a machine believe it has more memory than it does; the extra addresses do not correspond to new physical RAM, and some alias memory already in use, allowing accesses that bypass the isolation Windows and the processor normally enforce.
The disclosure followed a coordinated process, with affected vendors given technical details before publication.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named academic research with vendor confirmation, single-publisher relay
The technical account is specific and attributable: named institutions and researchers, a described mechanism from writable DIMM configuration data to memory aliasing, an enumerated demonstration set, and a survey of DDR4/DDR5 modules. External corroboration exists in the form of a coordinated disclosure, a Microsoft-assigned CVE and shipped mitigations. Ceiling is set by the cluster containing exactly one publisher relaying the research team's own framing, with no independent replication, no vendor statement of scope, and no primary-paper detail on how aliasing is achieved reliably across modules.
Vendor mitigation shipped, exposed hardware base unquantified independently
Concrete uptake exists on the response side: a CVE identifier, mitigations in the April 2026 Microsoft updates, and a stated baseline control (Secure Boot) that blocks the attack in its current form. On the exposure side, the survey shows real shipped product lines lacking write protection and others where partial protection blocked the attack, but affected models are unnamed and the market-share figure is an unverified researcher estimate. No in-the-wild exploitation, telemetry or enterprise remediation activity is reported, so real-world consequence beyond the lab remains unmeasured.
Headline capability leads, qualifiers arrive late
The demonstrated work is substantive and the framing is not fabricated, but the presentation front-loads 'strongest defenses bypassed' and a marketable attack name while the material limiters -- attacker must already hold privileged access, disclosure was coordinated, Microsoft already shipped mitigations, and Secure Boot blocks the attack in its current form -- appear only in the final lines. The unmethodologized market-share estimate also inflates the sense of blast radius, so claims sit modestly ahead of demonstrated real-world impact.
Academic disclosure publicity plus trade-outlet attention
Visible incentives are ordinary rather than hidden: an academic team promoting a branded finding ('Download More RAM') through quotable statements from three named researchers, and a security trade publisher whose audience rewards dramatic platform-bypass coverage. Coordinated disclosure and a vendor CVE cut the other way, indicating process discipline rather than pure publicity. No commercial sponsorship, vendor funding or product tie-in is disclosed in the source, so no stronger conflict can be asserted.
Internally consistent single-source account with verified vendor response
Confidence is supported by specificity, named accountable researchers, and an externally checkable CVE plus patch cycle, all of which make the core mechanism and impact claims credible. It is held down by the absence of any second publisher, of the primary paper's own data in the cluster, of named affected modules, and of any independent test of either the market-share estimate or the completeness of the shipped mitigations.
build
A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply1 distinct publisher
security
Microsoft is investigating whether its own August Patch Tuesday build breaks apps on Windows 111 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
product
Beijing, not Redmond, now sets the retirement date for Windows 10's China build1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 16, 2026