Skip to main content

Command Palette

Search for a command to run...

Windows Shared Memory: How Processes Share Data

Updated
6 min readView as Markdown
S
Computer Science student focused on systems programming, Linux, cybersecurity, and software development. I write technical articles and build projects to deepen my understanding of computer systems while documenting my learning journey.

Windows normally gives each process its own virtual address space.

This isolation is important for security and stability.

But sometimes processes need to communicate with each other and exchange data efficiently.

One solution is shared memory.

What Is Shared Memory?

Shared memory is a mechanism that allows two or more processes to access the same region of memory.

Normally:

Process A
└── Private Address Space

Process B
└── Private Address Space

With shared memory:

Process A ─────┐
               ↓
          Shared Memory
               ↑
Process B ─────┘

The processes have their own virtual address spaces, but Windows maps the same underlying memory into both processes.

Why Is Shared Memory Useful?

Shared memory can be very fast because processes can exchange data through memory instead of repeatedly copying large amounts of data through other communication mechanisms.

It can be useful for:

  • Inter-process communication

  • Sharing large amounts of data

  • Multimedia applications

  • Databases

  • High-performance applications

  • Communication between related components

How Does Shared Memory Work?

A simplified process looks like this:

Process A
    ↓
Create / Open Shared Memory
    ↓
Map Memory
    ↓
Write Data
    ↓
Shared Memory
    ↑
Read Data
    ↑
Process B

The exact Windows mechanism depends on how the shared memory is created and accessed.

File Mapping Objects

One important Windows mechanism for shared memory is the file mapping object.

Despite the name, a file mapping object does not necessarily mean that the processes are sharing an ordinary file.

Windows can create a memory-mapped region backed by the system paging mechanism.

Conceptually:

Process A
    ↓
File Mapping Object
    ↓
Mapped View
    ↓
Shared Memory
    ↑
Mapped View
    ↑
Process B

Windows APIs such as CreateFileMapping and MapViewOfFile are commonly associated with this mechanism.

Named Shared Memory

Shared memory can be associated with a name.

For example:

"SharedData"

      ↓

Process A → Shared Region ← Process B

Another process that knows the appropriate object name and has sufficient access can open the same object.

This makes named objects useful for communication between processes that don't have another direct way to exchange a handle.

Mapping the Same Memory

Each process can map the shared region at a different virtual address.

For example:

Process A
Virtual Address
0x10000000
      ↓
      ┌─────────────┐
      │             │
      │ Shared Data │
      │             │
      └─────────────┘
      ↑
      ↓
Process B
Virtual Address
0x50000000

The virtual addresses don't have to be identical.

They can still refer to the same underlying memory.

Shared Memory vs Shared Address Space

This distinction is important.

Processes generally do not share their entire virtual address spaces.

Instead, Windows can map specific memory regions into multiple processes.

Process A Address Space
┌───────────────────┐
│ Private Memory    │
├───────────────────┤
│ Shared Region     │
└───────────────────┘

Process B Address Space
┌───────────────────┐
│ Private Memory    │
├───────────────────┤
│ Shared Region     │
└───────────────────┘

Only the intended region is shared.

Synchronization

Shared memory creates an important problem.

What happens if two processes try to modify the same data at the same time?

For example:

Process A → Write
                ↓
           Shared Memory
                ↑
Process B → Write

Without proper synchronization, the processes could interfere with each other.

Windows provides synchronization mechanisms such as:

  • Mutexes

  • Events

  • Semaphores

  • Critical sections

  • Other synchronization primitives

These mechanisms help coordinate access to shared data.

Shared Memory and Race Conditions

A race condition can occur when the result of an operation depends on the timing of multiple threads or processes accessing shared data.

For example:

Process A ──→ Read
              ↓
         Shared Value
              ↑
Process B ──→ Modify

If access isn't properly coordinated, the result may be unexpected.

This is why shared memory usually needs synchronization when multiple participants can modify the same data.

Shared Memory and Security

Shared memory must also be protected.

Windows uses security mechanisms to control access to shared objects.

An application should not assume that every process is allowed to open or modify a shared memory object.

Access checks can depend on the security context of the requesting process and the security descriptor associated with the object.

Shared Memory in Malware Analysis

Shared memory is an important concept when analyzing suspicious Windows programs.

A malware analyst may investigate whether a process:

  • Creates shared memory

  • Opens shared memory objects

  • Maps unusual regions

  • Exchanges data with another process

  • Uses shared memory for coordination

Shared memory alone is not evidence of malicious behavior.

Legitimate applications use it extensively.

The analyst needs to understand the context and behavior surrounding the memory mapping.

Shared Memory vs Other IPC Mechanisms

Shared memory is one form of Inter-Process Communication (IPC).

Other Windows IPC mechanisms include:

  • Pipes

  • RPC

  • Sockets

  • Events

  • Messages

  • Shared memory

A simplified comparison:

Mechanism Basic Idea
Shared Memory Processes access common memory
Pipe Processes exchange a stream of data
RPC A process requests an operation from another process or service
Socket Processes communicate through network-style endpoints
Event Processes or threads signal one another

We'll explore Remote Procedure Calls (RPC) later in this series.

Shared Memory and DLLs

Shared memory can also be useful when multiple processes need access to common data.

Windows may map the same memory-backed resources into different processes while maintaining separate virtual address spaces.

This is another example of how Windows virtual memory provides flexibility.

A Simple Analogy

Imagine two students working on the same whiteboard.

Normally, each student has their own notebook.

Student A → Notebook A
Student B → Notebook B

But they can also use a shared whiteboard:

Student A ──┐
            ↓
       Whiteboard
            ↑
Student B ──┘

The whiteboard represents shared memory.

Both can see the same information, but they need rules to avoid writing over each other's work.

Final Thoughts

Windows shared memory allows multiple processes to access the same underlying memory region while maintaining separate virtual address spaces.

The key ideas are:

Separate processes → Shared memory region → Controlled access → Synchronization

Shared memory can provide extremely efficient communication, but it must be designed carefully to avoid race conditions and unauthorized access.

For Windows Internals and malware analysis, understanding shared memory also helps explain how processes exchange data and interact with other components.

In the next article, we'll explore Windows Drivers and see how Windows communicates with hardware and other low-level system components.

Windows Internals: The Architecture Behind Windows

Part 6 of 16

Go beyond the graphical interface and explore what really happens inside the Windows operating system. This series dives into the internal architecture and mechanisms that make Windows work—from processes, threads, memory management, and system calls to Windows APIs, the Registry, access tokens, security mechanisms, objects, handles, drivers, and kernel components. Instead of treating Windows as a black box, we'll break down what happens underneath the surface and understand how different components interact with each other. Whether you're interested in operating systems, cybersecurity, malware analysis, reverse engineering, or low-level programming, this series provides a structured journey into the inner workings of Windows. Learn Windows. Understand the internals. See what happens beneath the surface.

Up next

Windows Drivers: The Software That Connects Windows to Hardware

When you connect a keyboard, mouse, graphics card, storage device, or other hardware to a Windows computer, Windows needs a way to communicate with it. The hardware itself doesn't simply understand wh