Plug & Pwn Attack Exploits Windows PnP for SYSTEM Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Security researchers Alejandro Hernando and Borja Martínez revealed a new attack method called 'Plug & Pwn' that exploits the Windows Plug and Play (PnP) driver installation process. This attack allows malicious actors to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges without any user interaction, effectively achieving SYSTEM access with zero clicks. The research was presented at DEF CON 34 on August 11, 2026. The attack does not rely on a Windows kernel zero-day vulnerability but instead abuses the existing PnP detection and installation workflow. Affected systems include various Windows versions that utilize the PnP feature. The researchers have not disclosed specific CVEs related to this attack, but the implications for enterprise security are significant. Organizations are advised to review their PnP configurations and monitor for unusual activities. The full scope of impact is still being assessed.
Key Points: • The Plug & Pwn attack exploits Windows PnP to gain SYSTEM access without user interaction. • Researchers presented the findings at DEF CON 34 on August 11, 2026. • The attack does not require a kernel zero-day and targets existing PnP workflows.