New Plug and Play Attack Exploits Windows for SYSTEM Access

New Plug and Play Attack Exploits Windows for SYSTEM Access

First seen 12 Aug 2026, 19:07 UTC Feeds.4SysopsBleepingcomputernvd.nist.gov 79% similarity 67.5

Article Content

Browse articles
ThreatCluster

Researchers have unveiled a new attack method dubbed 'Plug and Pwn' that exploits Windows Plug and Play functionality to gain SYSTEM privileges. This vulnerability affects Windows 11 and potentially other versions, allowing attackers to execute code without user interaction. The attack can be performed remotely over RDP or by physically connecting a malicious USB device. It leverages the automatic installation of drivers and vendor software, which occurs with SYSTEM privileges, bypassing User Account Control (UAC). The research was presented at DEF CON 34 by Alejandro Hernando and Borja Martínez. Tools like FaceDancer were used to emulate USB devices during the demonstration. This attack is part of a broader family of vulnerabilities previously noted in 2021, highlighting ongoing risks associated with Windows device installation paths.

Key Points: • The 'Plug and Pwn' attack exploits Windows Plug and Play for SYSTEM access. • Attacks can occur remotely via RDP or through malicious USB devices. • The vulnerability affects Windows 11 and potentially other versions, bypassing UAC.

ThreatCluster AI How this analysis works

Timeline

2021-11-21
CVE-2019-10617 published
A vulnerability related to Windows Plug and Play was disclosed, affecting device installation processes.
BleepingComputer
2026-08-11
New Plug and Play attack chain demonstrated
Researchers showcased a new attack that turns automatic USB driver installation into SYSTEM-level code execution.
Feeds.4Sysops
2026-08-12
Research presented at DEF CON 34
Security researchers Alejandro Hernando and Borja Martínez presented their findings on the Plug and Pwn attack.
BleepingComputer

Community

Browse all →

Tracked Entities in This Story