Description

A newly disclosed Windows attack technique, dubbed “Download More RAM,” exploits writable Serial Presence Detect (SPD) data in certain DDR4 and DDR5 memory modules. Researchers demonstrated that attackers with existing local administrator privileges can manipulate RAM configuration to create memory aliasing, allowing access to protected memory areas. The technique can undermine Windows Virtualization-Based Security (VBS), bypass HVCI, weaken Microsoft Defender and interfere with third-party security products. Microsoft tracks the issue as CVE-2026-23670. The attack is primarily a hardware-assisted local privilege abuse rather than a conventional remote malware campaign. Researchers found writable SPD configurations in selected consumer memory products from Corsair, G.Skill and ADATA, although the survey was not comprehensive. The demonstrated attack requires local administrator access and targets Windows systems using vulnerable memory configurations. No specific geographic region or confirmed business victim was identified; the risk potentially affects organizations using susceptible hardware. Organizations should prioritize Microsoft security updates, as the April 2026 updates mitigate the documented attack chain. Security teams should also ensure Secure Boot is enabled and review BIOS/UEFI settings for SPD write-protection capabilities. Monitoring for unauthorized boot-configuration changes, vulnerable-driver loading and unusual kernel-memory activity can provide additional detection coverage. Hardware vendors should be consulted to confirm whether installed DIMMs provide adequate SPD protection.