ThreatCluster

Plug & Pwn Attack Exploits Windows PnP for SYSTEM Access

First seen 11 Aug 2026, 15:02 UTC GbhackersCybersecuritynews 90% similarity 65

Article Content

Browse articles
ThreatCluster

Security researchers Alejandro Hernando and Borja Martínez revealed a new attack method called 'Plug & Pwn' that exploits the Windows Plug and Play (PnP) driver installation process. This attack allows malicious actors to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges without any user interaction, effectively achieving SYSTEM access with zero clicks. The research was presented at DEF CON 34 on August 11, 2026. The attack does not rely on a Windows kernel zero-day vulnerability but instead abuses the existing PnP detection and installation workflow. Affected systems include various Windows versions that utilize the PnP feature. The researchers have not disclosed specific CVEs related to this attack, but the implications for enterprise security are significant. Organizations are advised to review their PnP configurations and monitor for unusual activities. The full scope of impact is still being assessed.

Key Points: • The Plug & Pwn attack exploits Windows PnP to gain SYSTEM access without user interaction. • Researchers presented the findings at DEF CON 34 on August 11, 2026. • The attack does not require a kernel zero-day and targets existing PnP workflows.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
Plug & Pwn attack revealed
Researchers Hernando and Martínez disclosed the attack method at DEF CON 34, demonstrating its ability to gain SYSTEM access.
Gbhackers
2026-08-11
Research published
The research details how the Windows PnP driver installation can be exploited without user interaction.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story