CVE Tools
Back to feed
Research Windows 11 privilege-escalation DDR4 Microsoft

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Help Net Security·By Sinisa Markovic··4 min read
CVE Tools coverage

University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.