Three new Windows flaws can bypass security, gain system privileges, and even install malware remotely

https://www.techspot.com/images2/news/ts3_thumbs/2025/12/2025-12-04-ts3_thumbs-5e0.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

What we know so far: Cybersecurity researchers have uncovered at least three new vulnerabilities that could potentially allow attackers to gain system privileges even on patched Windows computers. These include a memory configuration chip exploit named "Download more RAM," a zero-day flaw dubbed "ShieldBreak," and a "plug and pwn" exploit that could install malware remotely over RDP.

The "Download More RAM" vulnerability, which was presented at the 2026 USENIX Security Symposium in Baltimore, was discovered by researchers from the University of Birmingham and Durham University. It reportedly allows malicious actors to bypass Windows 11 security and gain system privileges without physical access by exploiting the lack of write protection on consumer memory modules.

The vulnerability allows anybody to remotely rewrite the Serial Presence Detect configuration chip that notifies the computer about...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE

Read more