ZeroHour

CVE-2026-23670

CVSS 3.1
5.7 medium
EPSS
<1%p19
Published
()
Modified
Description

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers found a script-only attack, 'Download More RAM', that rewrites DIMM configuration chips to bypass Windows 11 VBS and HVCI security boundaries.

Researchers at the University of Birmingham and Durham University showed that overwriting configuration data on unprotected DDR4/DDR5 module chips creates memory aliases that let attackers with existing privileged access defeat Virtualisation-based Security and HVCI, re-enable blocklisted drivers, kill EDR, and bypass group policy. Microsoft assigned CVE-2026-23670 and shipped mitigations in its April 2026 updates; systems with Secure Boot enabled are protected. Affected unprotected product lines are estimated at more than half of the high-performance consumer memory market and over 70% of the gaming segment.

Help Net Security · 29d agoVulnerabilityCVE-2026-236701