securityonline.info 8/11/2026, 9:01:29 AM · external

USB Plug and Play exploit grants SYSTEM access on Windows

USB Plug and Play exploit grants SYSTEM access on Windows
CyberSIXT Evidence Panel
Primary Source plugandpwn.com

RESEARCHERS demonstrated that inserting a USB device into a Windows system can allow attackers to gain SYSTEM privileges without needing administrator rights or a logged-in user. This exploit targets the Windows Plug and Play (PnP) feature, which automatically installs drivers. The attack, unveiled at DEF CON 34 by Alejandro Hernando and Borja Martinez, leverages vulnerabilities in drivers from various vendors, including Sierra Wireless and Sony.

The process involves emulating a USB device to redirect DNS and exploit co-installers, enabling arbitrary file writes. Affected systems are at risk, as standards for logical security are bypassed due to trust in signed packages. Mitigation strategies include blocking co-installers via Group Policy and disabling unnecessary RDP USB redirection. Given the public availability of exploit details, immediate action is advised.

View Primary Source Via securityonline.info

Article by CyberSIXT