Cybersecurity researchers have identified three critical vulnerabilities in Windows systems, including the "Download more RAM" memory exploit, which allow attackers to gain unauthorized system privileges remotely.
Key Points
- The "Download more RAM" exploit (CVE-2026-23670) allows remote attackers to bypass Windows 11 security by manipulating unprotected Serial Presence Detect chips on consumer memory modules.
- Major memory manufacturers including Corsair, G.Skill, and ADATA reportedly shipped hardware violating JEDEC guidelines by failing to implement necessary write protection.
- The ShieldBreak zero-day (CVE-2026-50656) enables privilege escalation within Microsoft Defender on Windows 10, Windows 11, and Windows Server environments.
- A "plug and pwn" vulnerability allows attackers to install malicious vendor drivers with system-level privileges remotely over RDP without requiring physical hardware access.
- Microsoft released mitigations in its April 2026 update, while Corsair and HWiNFO have introduced software tools to enable manual write protection for affected memory modules.