AUTO-UPDATED

Three new Windows flaws can bypass security, gain system privileges, and even install malware remotely

Cybersecurity researchers have identified three critical vulnerabilities in Windows systems, including the "Download more RAM" memory exploit, which allow attackers to gain unauthorized system privileges remotely.

Key Points

  • The "Download more RAM" exploit (CVE-2026-23670) allows remote attackers to bypass Windows 11 security by manipulating unprotected Serial Presence Detect chips on consumer memory modules.
  • Major memory manufacturers including Corsair, G.Skill, and ADATA reportedly shipped hardware violating JEDEC guidelines by failing to implement necessary write protection.
  • The ShieldBreak zero-day (CVE-2026-50656) enables privilege escalation within Microsoft Defender on Windows 10, Windows 11, and Windows Server environments.
  • A "plug and pwn" vulnerability allows attackers to install malicious vendor drivers with system-level privileges remotely over RDP without requiring physical hardware access.
  • Microsoft released mitigations in its April 2026 update, while Corsair and HWiNFO have introduced software tools to enable manual write protection for affected memory modules.

Why it Matters

These vulnerabilities represent a significant shift in threat modeling because they allow remote exploitation of hardware and system-level processes that previously required physical access. Organizations and users must prioritize updating their systems and hardware management software to prevent potential unauthorized access to sensitive security enclaves and corporate device settings.
TechSpot Published by Kishalaya Kundu
Read original