Microsoft Windows: 'Download More RAM' Attack Bypasses VBS and HVCI to Disable Defender
Researchers from the University of Birmingham have identified a critical vulnerability chain termed the 'Download More RAM' attack, which targets the Windows Hypervisor. By exploiting memory mapping flaws and virtualization handlers, the attack executes primitives to bypass Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI). This bypass allows for kernel-mode privilege escalation, enabling the execution of scripts that manipulate the Windows registry to disable Microsoft Defender and other core security mechanisms. The attack effectively creates a systemic 'kill-switch,' neutralizing hardware-backed isolation and preventing standard security alerts from triggering during the defense-neutralization phase.
Samsung Knox: Hypervisor-Level Kernel Protection Bypass CVE-2026-20971
CVE-2026-20971 is a critical vulnerability in the Samsung Knox security framework that facilitates a hypervisor-level bypass by exploiting a race condition within the kernel's process integrity validation mechanism. By leveraging this race condition primitive, an attacker can circumvent the Real-time Kernel Protection (RKP) provided by the Knox hypervisor. This flaw enables a transition from a kernel-level exploit to a complete hypervisor breach, resulting in Local Privilege Escalation (LPE) to a high-privilege or system context. Such an exploit effectively neutralizes Samsung's hardware-backed defense-in-depth strategy, allowing for the deployment of persistent rootkits capable of evading real-time integrity monitoring on enterprise-managed mobile devices.