Windows 11’s strongest security defenses can be bypassed without a screwdriver
ResearchWindows 11DDR4Our summary
University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.