Research Windows 11 privilege-escalation DDR4 Microsoft
Windows 11’s strongest security defenses can be bypassed without a screwdriver
CVE Tools coverage
University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.