Jessica Entwistle
August 17 2026
Help Net Security reports that researchers from the University of Birmingham and Durham University have demonstrated a technique to bypass some of Windows 11's strongest security protections without physically opening or modifying the target machine. The attack, named "Download More RAM," targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), the RAM sticks inside most computers. The researchers found that this chip does not verify the identity of the system or user making configuration requests, allowing an attacker with privileged access to manipulate memory settings in ways that can undermine security features such as Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI).
This research is a reminder that security protections are layered, and that even advanced features such as VBS and HVCI rely on assumptions about the integrity of underlying hardware and firmware. While the attack requires privileged access to the system, it highlights the importance of preventing attackers from gaining that level of access in the first place, and of monitoring for unusual system configuration changes. The research also underscores the value of defence in depth, where multiple layers of protection are in place so that the compromise of one layer does not lead to complete system failure. For UK organisations using Windows 11, this is a prompt to review whether endpoint detection and response (EDR) tools are configured to alert on unusual system configuration changes, and whether privileged access is appropriately controlled and monitored.
UK organisations should review whether endpoint detection tools are configured to alert on unusual system configuration changes, particularly those affecting memory settings, virtualisation features, or security protections. Ensure that privileged access to Windows 11 systems is tightly controlled, that administrative accounts are protected with multi-factor authentication, and that monitoring is in place to detect unusual activity by privileged users. Consider whether defence in depth principles are applied across endpoint security, with multiple layers of protection in place to reduce the impact of any single compromise. Review whether incident response processes are prepared to investigate and respond to unusual system configuration changes, and whether ownership of endpoint security is clear across the organisation.
Source: Help Net Security