Microsoft Windows: 'Download More RAM' Vulnerability Chain Bypasses VBS and HVCI
Researchers from the University of Birmingham and SeriSec have identified a critical vulnerability chain, dubbed "Download More RAM," that targets the Microsoft Windows kernel and hypervisor. The exploit leverages a sequence of three distinct vulnerabilities to circumvent Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI). By breaking the hardware-backed root of trust and undermining hypervisor-enforced memory isolation, attackers can achieve kernel-mode code integrity bypass. This allows for the execution of automated scripts designed to disable Microsoft Defender and other third-party Endpoint Detection and Response (EDR) solutions. The chain is reportedly delivered via the "PolitePaul" service, requiring minimal user interaction and enabling remote execution without physical access.
Samsung Knox: Hypervisor-Level Kernel Protection Bypass CVE-2026-20971
CVE-2026-20971 is a critical vulnerability in the Samsung Knox security framework that facilitates a hypervisor-level bypass by exploiting a race condition within the kernel's process integrity validation mechanism. By leveraging this race condition primitive, an attacker can circumvent the Real-time Kernel Protection (RKP) provided by the Knox hypervisor. This flaw enables a transition from a kernel-level exploit to a complete hypervisor breach, resulting in Local Privilege Escalation (LPE) to a high-privilege or system context. Such an exploit effectively neutralizes Samsung's hardware-backed defense-in-depth strategy, allowing for the deployment of persistent rootkits capable of evading real-time integrity monitoring on enterprise-managed mobile devices.