The problem lies in a configuration chip on certain DDR4 and DDR5 DIMMs that tells the system how much memory is installed. On affected modules, this chip lacks write protection, allowing software to modify the information it contains. This can then make Windows believe that the system has twice as much RAM as it actually does.
The researchers used this technique to bypass several of Windows’ security measures, including Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). They also demonstrated attacks that can disable antivirus and EDR software, re-enable vulnerable drivers previously blocked because of their use in malware campaigns, compromise locked-down corporate systems, and bypass kernel-level game anti-cheat protections.
