Virtualization-based Security

Winsage
September 9, 2026
Microsoft's September 2026 security update revealed 973 vulnerabilities, with 113 classified as critical. Two actively exploited vulnerabilities are CVE-2026-81963 (Windows Update Stack, elevation of privilege, CVSS 7.8) and CVE-2026-85880 (Windows ALPC, elevation of privilege, CVSS 7.8). Among the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Notable vulnerabilities include: - CVE-2026-69676: RCE in Windows Kerberos, CVSS 8.8, authentication bypass. - CVE-2026-69852: RCE in Windows RRAS, CVSS 7.5, heap-based buffer overflow. - CVE-2026-72957: RCE in Windows Deployment Services, CVSS 7.8. - CVE-2026-69854: Elevation of privilege in Spring Cloud Azure, CVSS 9.0, improper authentication. - CVE-2026-83501: Information disclosure in Windows VBS, CVSS 5.5. - CVE-2026-69730: RCE in Windows DNS Server, CVSS 9.8. Less likely to be exploited vulnerabilities include: - CVE-2026-69845: RCE in Windows DHCP Server, CVSS 9.8, heap-based buffer overflow. - CVE-2026-65772: Vulnerability in Microsoft Dynamics 365 On-Premises, CVSS 8.8, deserialization of untrusted data. - CVE-2026-66302: RCE in Skype for Business, CVSS 9.8. Additional critical vulnerabilities include: - CVE-2026-62916: Elevation of privilege in Microsoft Entra ID, CVSS 9.1. - CVE-2026-83941: Elevation of privilege in Entra ID, CVSS 9.9. - CVE-2026-80098: Vulnerability in Copilot Studio, CVSS 9.3, improper verification of cryptographic signatures. Talos is releasing a new Snort ruleset to detect attempts to exploit these vulnerabilities, with specific SIDs for Snort 2 and Snort 3 rule coverage.
Winsage
September 5, 2026
Memory Integrity enhances Windows 11 security by allowing only verified kernel-mode code to load, blocking unsigned rootkits and improving defenses against driver-based kernel attacks. It requires specific hardware for optimal functionality. The combination of Hypervisor-Protected Code Integrity (HVCI) and Virtualization-Based Security (VBS) may result in a performance decrease in gaming, with reported slowdowns of up to 15 percent. Microsoft acknowledged in 2022 that these features might impact gaming performance and advised gamers to consider temporarily disabling them for better performance, especially on older hardware. Tom’s Hardware reiterated this recommendation to balance security and user experience.
Winsage
September 4, 2026
Microsoft is expanding the memory integrity protection feature in Windows 11, starting in October. This enhancement aims to strengthen security at the kernel level against sophisticated attacks. Memory integrity protection operates in the background with minimal user configuration. It utilizes Virtualization-based Security (VBS) to create isolated virtual environments for added protection. The system can install security hotpatches without requiring a hard restart, beneficial for critical environments. Large organizations will automatically benefit from this enhancement, while devices with memory integrity disabled will not have it activated automatically. The rollout will enable VBS by default for users, who can choose to disable it but should do so with caution.
Winsage
September 3, 2026
Microsoft plans to automatically activate Memory Integrity on a broader range of eligible systems starting October 2026, rolling it out through standard Windows quality updates. Prior to activation, Windows will assess hardware, drivers, and performance to ensure compatibility. Memory Integrity, part of Virtualization-based Security (VBS), uses the Windows hypervisor to create a secure environment for integrity checks on kernel code. Compatibility with drivers is crucial, as many older applications may not meet the stricter standards required for HVCI. Potential compatibility issues may arise with anti-cheat solutions, third-party input methods, and banking protection programs, which could lead to software malfunctions or boot failures. A readiness check will evaluate hardware compatibility, with eligible systems including Intel processors from the 8th generation, AMD processors from Zen 2, and Qualcomm Snapdragon 8180 or newer, along with specific RAM and storage requirements. The rollout will be gradual, and users who previously disabled HVCI will not face unexpected reactivation. Microsoft recommends updating affected applications or drivers in case of compatibility issues.
Winsage
September 2, 2026
Microsoft will automatically enable its Memory Integrity feature on more eligible Windows PCs starting in October 2026, enhancing kernel-level protection. PCs with Memory Integrity currently disabled will retain their settings. Windows will also activate Virtualization-based Security (VBS) where necessary, which supports Memory Integrity. An automatic assessment will determine device eligibility based on hardware capabilities and compatibility. The rollout applies to Windows 11 installations meeting specific hardware specifications, including an 8th Generation or newer Intel processor or AMD Zen 2 or newer processor, at least 8GB of RAM, an SSD with a minimum of 64GB, compatible drivers, and enabled hardware virtualization. Memory Integrity, also known as Hypervisor-Protected Code Integrity (HVCI), has been part of Windows since the Windows 10 era and is now more integral to Windows 11 security for new installations. However, it may impact gaming performance, leading some gamers to disable it, which Microsoft has acknowledged in its recommendations.
Winsage
September 2, 2026
Microsoft plans to enhance security measures across eligible devices by activating "Memory Integrity Protection" starting in October 2026. This feature operates at the kernel level to defend against cyber threats and requires minimal configuration. It is built on Virtualization-based Security (VBS) and aims to protect critical components of the Windows operating system from tampering.
Winsage
August 14, 2026
Researchers from the University of Birmingham and Durham University discovered a vulnerability in consumer DDR4 and DDR5 memory chips, termed "Download more RAM," which allows attackers to misreport memory configuration, potentially doubling the perceived RAM. This manipulation enables unauthorized access to memory allocations, bypassing Windows' Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI), and disabling antivirus software. The vulnerability affects major manufacturers like Corsair, G.Skill, and ADATA, which collectively hold over 55% of the high-performance memory market. Microsoft has patched the vulnerability, cataloged as CVE-2026-23670, with a medium severity score of 5.7/10, in the April 2026 Patch Tuesday update. Corsair has introduced a feature to enable write protection on their memory modules, and other tools are available for additional protection.
Tech Optimizer
August 14, 2026
Researchers have identified a significant vulnerability in consumer DDR4 and DDR5 memory modules, known as the “Download more RAM” flaw, which allows attackers to bypass advanced Windows security features, including Virtualization-Based Security (VBS) and Hypervisor Code Integrity (HVCI). This vulnerability enables the manipulation of configuration reports from RAM, misleading the system about its actual memory capacity, which can disable antivirus protections and allow the reintroduction of outdated drivers. The exploit can be executed via a single-click script, leading to security failures. Microsoft has released a patch for CVE‑2026‑23670 to enhance memory write protection against such exploits.
Search