Birmingham and Durham researchers bypass Windows 11 VBS/HVCI with Download More RAM
This digest was compiled by AI from multiple sources — links to the originals are below.

Researchers from the University of Birmingham and Durham University have bypassed Windows 11's Virtualization-Based Security and Hypervisor-Enforced Code Integrity by rewriting a configuration chip on RAM modules. The attack, named Download More RAM, requires only privileged access and a script, and can reactivate vulnerable drivers, disable antivirus and EDR software, and extract data from VBS enclaves.
Key Facts
- University of Birmingham and Durham University researchers bypassed Windows 11 VBS and HVCI by rewriting the SPD configuration chip on RAM modules.
- The Download More RAM attack requires only privileged access and a script, not physical opening or modification of the machine.
- The technique can re-enable hundreds of blocklisted vulnerable drivers, kill antivirus and EDR software, and extract data from VBS enclaves.
- Professor Tom Chothia of the University of Birmingham said previous attacks of this kind needed a screwdriver and physical access.
- Lead author Sam Collins said Microsoft VBS "blindly trusted the shaky ground it stood on."
Download More RAM
The attack, named Download More RAM, targets a small configuration chip found on Dual In-line Memory Modules, the RAM sticks inside most desktops and laptops. On several consumer memory modules, nothing stops software from rewriting critical parts of that chip. An attacker who overwrites that information can make a machine believe it has more memory than it does, and the extra addresses alias memory already in use. These aliases allow accesses that bypass the isolation Windows and the processor normally enforce. The attack assumes the attacker has already gained privileged access to the system.
Security Bypass Capabilities
Once memory aliasing is set up, the team demonstrated they could reach into parts of the system Windows is built to keep off-limits. The researchers showed an attacker could turn on hundreds of blocklisted drivers with known vulnerabilities, including drivers previously associated with malware and ransomware. The attack can kill antivirus and endpoint detection and response software, disabling tools that would normally monitor activity and flag attacks. It can reach inside Virtualization-based Security enclaves and pull out data meant to stay isolated from the rest of the machine. It can also get past corporate device-management rules, including group-policy restrictions used on enterprise and university-managed machines, and kernel-level anti-cheat protections in games.
Researcher Statements
Tom Chothia, professor of cyber security at Birmingham, said: "Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees." He said previous attacks of this kind needed a screwdriver and physical access to the machine, while Download More RAM just needs a script. Lead author Sam Collins stated that in this scenario Microsoft VBS "blindly trusted the shaky ground it stood on."
1 source
Birmingham and Durham researchers bypass Windows 11 VBS/HVCI with Download More RAM






