Three new Windows flaws can bypass security, gain system privileges, and even install malware remotely
The "Download More RAM" vulnerability, which was presented at the 2026 USENIX Security Symposium in Baltimore, was discovered by researchers from the University of Birmingham and Durham University. It reportedly allows malicious actors to bypass Windows 11 security and gain system privileges without physical access by exploiting the lack of write protection... Read Entire Article
Three previously unknown Windows security flaws could enable attackers to bypass safeguards, acquire elevated system privileges, and even install malware remotely. Known as "Download More RAM," a memory configuration chip exploit, this flaw was unveiled at the 2026 USENIX Security Symposium by researchers from the University of Birmingham and Durham University.
It allows malicious actors to circumvent Windows 11 security and elevate privileges without physical access by exploiting unprotected write capabilities on consumer memory modules. By falsifying data, attackers can trick the computer into believing it has double the actual RAM, enabling them to map pseudo-addresses and establish a backdoor into memory.
This could allow hackers to enable old drivers with known vulnerabilities, disable anti-malware software, breach virtualization-based security enclaves, manipulate corporate device management settings, and even bypass kernel-level anti-cheat systems in video games. The vulnerability, identified as CVE-2026-23670, has been acknowledged by both Microsoft and Corsair.
Microsoft issued mitigations in its April 2026 update, and Corsair included a feature in its iCue hardware management tool to enable write protection on DIMMs. Another zero-day flaw, called "ShieldBreak," was discovered by bug hunter Nightmare Eclipse and tracked as CVE-2026-50656. It is an elevation-of-privilege vulnerability in Microsoft Defender that can bypass the RoguePlanet patch, allowing attackers to gain system privileges on Windows 10, 11, and Server, provided Microsoft Defender is active.
Lastly, a new attack named "Plug and Pwn" was described by Alejandro Hernando and Borja Martinez at DEF CON 34 in Las Vegas. This exploit takes advantage of Windows' automatic hardware identification and driver installation process to install signed vendor driver packages with system-level privileges, potentially without requiring admin privileges or a logged-in user.
The researchers demonstrated the attack remotely over Remote Desktop Protocol (RDP) without connecting any physical USB hardware to the target device.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.