Three New Windows Flaws Turn Your RAM, Your USB Drive, and Even Windows Defender Against You

Researchers have uncovered three new Windows security flaws that could let attackers bypass your device’s defenses and steal sensitive data.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Within just a few weeks, security researchers have uncovered three Windows vulnerabilities that could give attackers privileged access to a system without physical access or a password.[1]

One vulnerability — “Download More RAM” — can abuse a memory-related feature and open backdoors into system parts that were otherwise off-limits. Another, called ShieldBreak, can turn Microsoft Defender’s own scanning process against you.

And a third one, called “Plug and Pwn,” can exploit a Windows feature (auto-installing drivers) you probably didn’t even know existed to install vulnerability-inflicted drivers even without hardware.

Together, these vulnerabilities can turn the very hardware and software designed to protect your system against you, potentially allowing attackers to gain privileged access, disable security protections, steal sensitive data, and install malicious software.

Here’s how each of these Windows vulnerabilities works and, more importantly, what you can do to protect yourself.

In this article
How the “Download More RAM” attack works
Two more ways attackers can bypass Windows security
What can you do to protect yourself
Bottom line

How the “Download More RAM” attack works

The vulnerability, known as “Download More RAM,” allows an attacker to rewrite the Serial Presence Detect (SPD) configuration chip. The SPD is a small chip on every RAM stick that tells the system how much memory is installed.

This rewriting tricks the system into believing that the RAM has more memory than it actually does.

Your computer then maps the extra addresses back into real memory that’s already in use. This means that two different addresses now point to the same physical memory. While one is an alias, the other is the real system memory.

When this happens, built-in protections such as virtualization-based security and hypervisor-enforced code integrity also fail. The system configures permissions based on addresses and not the physical memory itself.

Now, since the attacker’s alias addresses are not restricted, they can read and write to it freely. Once inside, the attackers could do a wide variety of damage:

  1. Turn back old vulnerable drivers
  2. Disable antivirus and endpoint detection systems
  3. Bypass corporate device management locks
  4. Read Microsoft’s most isolated security zones
  5. Defeat anti-cheat systems

Researchers conducted a survey of popular DDR4 and DDR5 memory modules and found that at least three manufacturers (Corsair, G.Skill, and ADATA) sell product lines where the configuration chip is unprotected, which is against the Joint Electron Device Engineering Council (JEDEC) guidelines.

These vendors make up 70% of the gaming segment and 55% of the high-performance consumer memory market, potentially leaving a large number of systems vulnerable to this malware.

However, this doesn’t mean that if you’re using one of these unprotected chips, you’re automatically exposed to the vulnerability. This vulnerability, tracked as CVE-2026-23670, doesn’t let an attacker compromise a Windows 11 system simply by knowing its IP address.

Although the researchers didn’t specifically identify a delivery method, an attacker would first need to get malicious code onto the target machine and obtain elevated privileges before exploiting this vulnerability.

This could potentially involve techniques such as phishing or malicious software, but the vulnerability itself doesn’t provide the initial means of compromise. It’s not a remote, no-click attack.

Two more ways attackers can bypass Windows security

Another vulnerability, tracked as CVE-2026-50656, was discovered by security researcher Nightmare Eclipse. Dubbed ShieldBreak, the proof of concept demonstrates that Microsoft’s earlier patch for the RoguePlanet vulnerability may have been ineffective.

In June 2026, the same researcher discovered RoguePlanet, a flaw that allowed attackers to swap files while Microsoft Defender was scanning them and gave the attacker SYSTEM-level privileges.

Microsoft subsequently released a patch to address the issue. However, ShieldBreak suggests that the update closed only one entry point while leaving the underlying weakness exposed through another pathway.

Like Download More RAM, ShieldBreak requires the attacker to already have some form of code execution or local access to the system, but not administrative or privileged access, since the exploit's entire purpose is to escalate an unprivileged user to SYSTEM.

ShieldBreak bypasses a vulnerability originally rated High with a CVSS score of 7.8 (CVE-2026-50656), and, at the time of writing, no Microsoft patch closes the bypass.

Researchers have also discovered another flaw, “Plug and Pwn,” that abuses Windows’ Plug and Play (PnP) auto-installation feature.

When Windows detects new hardware, such as a USB device, it can automatically fetch a matching, signed vendor driver package and install it with SYSTEM-level privileges without triggering a UAC prompt.

A tool called FaceDancer could trick Windows into fetching these vendor driver packages even when no physical device was connected. In some cases, the vendor drivers themselves contain exploitable vulnerabilities.

An attacker could potentially chain these flaws together, starting without elevated privileges and ultimately gaining full SYSTEM-level control of the machine, allowing them to disable security protections, install malware, and steal data.

What’s particularly concerning is that this flaw can be exploited without any physical hardware and entirely remotely through Remote Desktop Protocol (RDP). It requires neither administrator privileges nor an actively logged-in user, making the vulnerability significantly more serious.

What can you do to protect yourself

None of these attacks mean that you are defenseless. There are several actions you can take right now to reduce your exposure and shut the door on these vulnerabilities.

  1. Enable Secure Boot: Secure Boot is the single most effective fix, as researchers have confirmed that machines running Secure Boot are already protected against “Download More RAM” in its current form. You can check this by viewing your system’s UEFI Firmware Settings and ensuring that Secure Boot is toggled on.
  2. Install Windows updates: Microsoft has already issued an update for “Download More RAM” in its April 2026 security update. Ensure that your system is up to date and enable automatic updates going forward so that any critical vulnerabilities are automatically patched.
  3. Enable RAM write protection: If your system does not support Secure Boot, you can enable RAM write protection. Corsair introduced a new feature to its iCUE software, which allows users to retroactively enable write protection on memory modules. Even if you’re not using Corsair, there’s a free tool called HWiNFO that allows you to mitigate the issues on non-Corsair models.
  4. Practice proper online hygiene: Because the attack requires the malicious party to run code on your device, make sure you don’t click on unknown links from senders you don’t recognize, as they could be phishing attempts. Never open suspicious attachments or download software from unofficial sources.
  5. Don’t rely on free antivirus: Since ShieldBreak specifically targets the Microsoft Defender scanning engine, you should not rely solely on Defender for protection. Consider deploying a third-party antivirus program as an additional layer of protection, particularly until Microsoft releases an effective fix.
  6. Disable co-installers: You can partially mitigate the Plug and Pwn attack by disabling co-installers through the Windows Registry. While this doesn’t address the underlying vulnerability, it can block some of the demonstrated attack chains.
  7. Manage USB permissions: You can also use Group Policy or endpoint management tools to restrict which USB devices are permitted to install Windows drivers. This is particularly useful on shared or corporate systems, where limiting hardware and driver installation to trusted devices can reduce the attack surface.

Bottom line

These recently discovered vulnerabilities exploit various parts of your Windows system and, in some cases, do not require physical access or passwords to gain privileged access.

While Microsoft has released a patch for Download More RAM, along with updates from Corsair and other vendors, there are currently no patches available for ShieldBreak or the Plug and Play attacks. This makes it important to strengthen your Windows settings and close security gaps on your end.

You could use a reliable third-party antivirus to mitigate ShieldBreak while Microsoft works on a patch. Similarly, consider disabling co-installers and managing USB permissions to reduce your exposure to Plug and Pwn attacks.

#1 Antivirus Protection From an Award-Winning Brand You Trust
5.0
Editorial Rating
Get Deal
On Norton 360 Antivirus's website
2026 Editors’ Choice
Best All-In-One Antivirus
Antivirus Software
Norton 360 Antivirus
PROMOTION: Save Up to 60%
  • Our #1 rated antivirus that scores 18/18 on AV-TEST across Windows, macOS, and Android, verified across multiple test rounds
  • Passed every malware, drive-by download, and phishing detection test we ran, quarantining threats automatically
  • Backed by a 100% Virus Protection Promise: if Norton can't remove a virus, you get your money back

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Three new Windows flaws can bypass security, gain system privileges, and even install malware remotely