Windows 11 DIMM Metadata Rewrite Bypasses Defenses

Researchers found a Windows 11 bypass in which privileged software can rewrite writable DIMM Serial Presence Detect (SPD) metadata on some consumer memory modules, tracked as CVE-2026-23670. Microsoft issued mitigations in April 2026. The attack changes the memory stick’s configuration data so the machine believes it has more RAM than it really does. That creates aliased addresses over the same physical memory, breaking the isolation Windows expects and letting code reach protected areas; the researchers showed this can disable EDR and antivirus, re-enable blocked drivers, and reach Virtualization-based Security (VBS) memory without physical tampering. For Windows 11 fleets that use consumer DIMMs with writable SPD, the exposure sits after local privilege compromise: platform defenses that are supposed to hold inside the OS can be undermined from within. The risk is not the RAM setting itself, but the trust Windows places in hardware metadata once an attacker already has control.

Part of the PlainSec briefing for 2026-08-17

Every edition of this story: Windows 11 DIMM Metadata Rewrite Bypasses Defenses

Sources