CVE Tools

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Help Net SecurityBy Sinisa Markovic

ResearchWindows 11DDR4

Our summary

University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store