• 'This one just needs a script': Researchers find ultimate Windows

    From TechnologyDaily@1337:1/100 to All on Fri Aug 14 17:15:22 2026
    'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

    Date:
    Fri, 14 Aug 2026 16:05:00 +0000

    Description:
    Microsoft fixed it as part of the April Patch Tuesday cumulative update, but there are other fixes and mitigations available, too.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researchers uncovered Download more RAM flaw in consumer DDR4/DDR5 memory Attack bypassed Windows VBS and HVCI, disabling antivirus and protections Microsoft patched CVE202623670; tools now help enable memory write protection Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security
    measures, disable antivirus software, and expose the target device to full system takeover.

    All of this, it seems, could have been possible with a very simple script,
    and a single click from the victims side. Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands. Latest Videos From TechRadar Watch full video here: Download more RAM During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called Download more RAM.

    According to the researchers, some consumer memory chips (DDR4 and DDR5 DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device think it has twice as much RAM memory as it actually has. You may like Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day Microsoft just released its biggest Patch Tuesday ever Microsoft 365 Copilot could be turned into a one-click data theft tool

    The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processors, and Windows protection.

    This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    VBS, first introduced with Windows 10 , is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code
    can run in the Windows kernel.

    The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable
    drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections.

    The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. What to read next Microsoft vows to make Windows 11 run better with 8GB of
    RAM Experts find attackers can exploit decades-old UEFI flaws to gain access to key systems Microsoft confirms two major Defender security issues so update now or face possible attack

    "Our work exploits the fact that all processes share the same memory to
    bypass Windows' strongest security guarantees, said Professor Tom Chothia, from the University of Birmingham. Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread." Who is vulnerable and how to stay safe The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesnt mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).

    Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure.

    Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as
    CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave which allows an authorized attacker to bypass a security
    feature locally.

    The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability.

    Corsair added a feature to its iCue tools that lets users retroactively
    enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.

    The Download More RAM attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk, said Dr Marius Muench, from the University of Birmingham.

    Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/this-one-just-needs-a-script-researcher s-find-ultimate-windows-kill-switch-which-can-disable-antivirus-with-almost-no -user-interaction


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)