Windows 11 Gets Memory Integrity Boost Amid Kernel Attack Fears
Microsoft is taking steps to enhance the security of its Windows 11 operating system. The company plans to enable memory integrity protection on eligible devices, which will help prevent attacks targeting the Windows kernel.
The feature relies on Virtualization-based Security (VBS) and only allows trusted kernel-mode code and drivers to run on affected PCs. This means that any malicious code attempting to infiltrate the system will be blocked by default.
Memory integrity is already enabled by default on Secured-core PCs and after a clean install of Windows 11, but some manufacturers may choose to disable it, and IT admins can also opt out using management tools.
However, Microsoft has cautioned that older processors may experience performance issues due to the feature's emulation of Mode-Based Execution Control and Guest Mode Execute Trap capabilities. The company is proceeding with caution, evaluating readiness before enabling memory integrity on eligible devices.