2026-08-13 バーミンガム大学
<関連情報>
- https://www.birmingham.ac.uk/news/2026/attackers-can-bypass-microsofts-flagship-windows-security-defences-without-physical-access
- https://www.usenix.org/conference/usenixsecurity26/presentation/collins
もっとRAMをダウンロード:悪質なメモリでWindowsオペレーティングシステムの防御を解体する
Download More RAM: Dismantling Windows Operating System Defences with Mischievous Memory
Sam Collins, Tom Chothia, William Burgess, and Marius Muench
2026 USENIX Security Symposium
Virtualisation-Based Security (VBS) is the cornerstone of modern Windows desktop defences, relied upon by both the operating system and third-party software, with a virtualised secure kernel providing strong security guarantees against even privileged attackers. In this paper, we introduce Download More RAM, software-only memory aliasing attack that breaks these guarantees without physical access. On systems running the most common consumer DIMMs, our attack allows arbitrary memory read/write, letting a privileged user compromise the OS at every level, including the secure kernel, Hypervisor Enforced Code Integrity (HVCI), and all defences it provides. With this access we develop a series of case study attacks targeting VBS-protected processes, Windows Defender, anti-virus & EDR software, and game anti-cheats. Our work breaks the strongest security guarantees offered by the Windows OS, questioning key trust assumptions on such systems. Microsoft have assigned CVE-2026-23670 to our findings and issued a patch that partially mitigates our attack.


