Bleepingcomputer
New Plug and Play Attack Exploits Windows for SYSTEM Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers have unveiled a new attack method dubbed 'Plug and Pwn' that exploits Windows Plug and Play functionality to gain SYSTEM privileges. This vulnerability affects Windows 11 and potentially other versions, allowing attackers to execute code without user interaction. The attack can be performed remotely over RDP or by physically connecting a malicious USB device. It leverages the automatic installation of drivers and vendor software, which occurs with SYSTEM privileges, bypassing User Account Control (UAC). The research was presented at DEF CON 34 by Alejandro Hernando and Borja Martínez. Tools like FaceDancer were used to emulate USB devices during the demonstration. This attack is part of a broader family of vulnerabilities previously noted in 2021, highlighting ongoing risks associated with Windows device installation paths.
Key Points: • The 'Plug and Pwn' attack exploits Windows Plug and Play for SYSTEM access. • Attacks can occur remotely via RDP or through malicious USB devices. • The vulnerability affects Windows 11 and potentially other versions, bypassing UAC.