Download More RAM: When Memory Lies, Security Falls
Download More RAM is a RAM vulnerability exploit where attackers rewrite a configuration chip on certain DDR4 and DDR5 memory modules so Windows believes more memory is installed than exists, creating alias addresses that let them bypass operating system and processor protections using software alone. That should alarm PC enthusiasts: the strongest Windows 11 security defenses can be undone not with a screwdriver, but with a script. Researchers from the University of Birmingham and Durham University showed that this flaw in how some consumer DIMMs report their configuration lets privileged malware break past virtualization-based protections that were marketed as a key reason to adopt Windows 11’s stricter hardware requirements. In other words, if your RAM misreports itself, Windows’ promise of isolation is built on sand.

How a Tiny Chip Turns a Script Into a Windows 11 Security Bypass
The attack works because a small configuration chip on affected DIMMs never checks who is asking to change its data. On several consumer modules, that chip lacks write protection, so software with high privileges can rewrite critical fields and convince the system it has more RAM than it does. Those extra addresses don’t map to new physical memory; they alias existing locations, breaking the isolation that Windows and the CPU rely on for defenses like Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). This turns a RAM configuration quirk into a PC security threat that reaches into areas the secure kernel should keep off-limits. Previous attacks of this kind demanded physical access and hardware tampering; now, researchers have shown it “just needs a script,” automating alias creation, reboot, and antivirus shutdown with a single click once admin access is gained.
Who Is Exposed: It’s Not Only Windows 11 Gamers
This isn’t a niche curiosity affecting a rare stick of RAM. Researchers found that Corsair, G.Skill, and ADATA each ship at least one consumer memory line where the configuration chip is completely unprotected, and they estimate these lines cover more than half of the high-performance consumer market and over 70% of the gaming segment. Because the flaw lives in the memory module, not in Windows itself, it threatens all supported Windows versions—Windows 10 and Windows 11 both need attention. If you build your own PC or buy performance-focused systems, you’re in the risk band by default. The uncomfortable truth for enthusiasts is that chasing high-end memory without checking its safety features can undermine every other security decision you’ve made. Brand alone doesn’t tell you if you’re safe; the write-protection status of your specific modules does.
What PC Enthusiasts Should Do Today
The good news is that there are clear steps you can take now. Microsoft assigned the issue CVE-2026-23670 and shipped mitigations in its April 2026 security updates, with systems that have Secure Boot enabled protected against the attack in its current form. That means every serious PC user should verify Secure Boot is on and install the latest cumulative Patch Tuesday updates for Windows 10 or Windows 11. On the hardware side, treat RAM like a security component: Corsair’s iCUE software can enable write protection on affected modules, HWiNFO offers similar controls for non-Corsair memory, and some motherboards expose BIOS options to block writes to these configuration chips. If your gear supports these mitigations and you leave them disabled, you’re effectively inviting any future exploit that targets the same weak spot.
Building Fast PCs Means Owning Hardware-Level Security
PC builders have long treated RAM as a performance playground: timings, frequencies, and RGB flair. Download More RAM shows it is also a security boundary—and one that can collapse. When an overlooked configuration chip can turn privileged malware into a Windows 11 security bypass, enthusiasts can’t pretend firmware and module design are someone else’s problem. You should pick memory with proper write protection, keep an eye on vendor advisories, and assume that any component with configuration storage can be abused if it isn’t locked down. This research doesn’t mean Windows’ protections are worthless; it means they depend on hardware telling the truth. If you want your PC to be more than a fast target, start treating hardware-level mitigations and timely security patches as part of the build process, not an afterthought.






