物理的アクセスなしでもWindowsのセキュリティ防御を回避可能であることを研究が示す(Attackers bypass Windows security without physical access)

2026-08-13 バーミンガム大学

バーミンガム大学とダラム大学の研究チームは、Windows 11の強力なセキュリティ機構を、標的PCへの物理的アクセスなしに突破できる新たな攻撃手法「Download More RAM」を発見した。一般的なDDR4・DDR5メモリの一部では、メモリ容量をコンピューターに伝える設定チップに書き込み保護がなく、ソフトウェアから設定を書き換えることで実際には存在しないメモリアドレスを生成できる。これによりメモリエイリアスを作成し、脆弱なドライバーの再有効化、ウイルス対策・EDRの無効化、VBSやHVCIによる保護領域へのアクセス、企業向け端末管理の回避などが可能になる。研究チームは一連の攻撃を自動実行するスクリプトも実証した。MicrosoftはCVE-2026-23670として対策を実施し、Secure Boot有効環境では現状の攻撃を防御できるとしている。

<関連情報>

もっとRAMをダウンロード:悪質なメモリでWindowsオペレーティングシステムの防御を解体する
Download More RAM: Dismantling Windows Operating System Defences with Mischievous Memory

Sam Collins, Tom Chothia, William Burgess, and Marius Muench
2026 USENIX Security Symposium

Virtualisation-Based Security (VBS) is the cornerstone of modern Windows desktop defences, relied upon by both the operating system and third-party software, with a virtualised secure kernel providing strong security guarantees against even privileged attackers. In this paper, we introduce Download More RAM, software-only memory aliasing attack that breaks these guarantees without physical access. On systems running the most common consumer DIMMs, our attack allows arbitrary memory read/write, letting a privileged user compromise the OS at every level, including the secure kernel, Hypervisor Enforced Code Integrity (HVCI), and all defences it provides. With this access we develop a series of case study attacks targeting VBS-protected processes, Windows Defender, anti-virus & EDR software, and game anti-cheats. Our work breaks the strongest security guarantees offered by the Windows OS, questioning key trust assumptions on such systems. Microsoft have assigned CVE-2026-23670 to our findings and issued a patch that partially mitigates our attack.

1601コンピュータ工学
ad
ad
Follow
ad
タイトルとURLをコピーしました