Ethical Hacking News
Recently, researchers have discovered a critical vulnerability in Windows Plug and Play that enables an attacker to execute privileged code on a fully updated system. This discovery has significant implications for enterprise security and raises concerns about the potential for full system takeover. Learn more about the "Plug And Pwn" technique and how it can be exploited.
A critical vulnerability has been discovered in Windows Plug and Play, allowing attackers to execute privileged code on fully updated systems. The "Plug And Pwn" technique exploits a legitimate installation path combined with weaknesses in signed third-party packages. An attacker can use this vulnerability to install a malicious service on a system, giving an authenticated low-privilege user SYSTEM code execution. The vulnerability can be triggered remotely over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled. Microsoft has acknowledged the vulnerability and advised administrators to keep software up-to-date and enforce strict security policies.
In a stark reminder of the importance of robust cybersecurity measures, researchers have recently discovered a critical vulnerability in Windows Plug and Play, allowing an attacker to execute privileged code on a fully updated system. This discovery has significant implications for enterprise security and raises concerns about the potential for full system takeover.
Researchers Alejandro Hernando and Borja Martinez revealed their findings at DEF CON 34, detailing how the "Plug And Pwn" technique exploits a legitimate installation path combined with weaknesses in signed third-party packages. According to the researchers, an attacker can use this vulnerability to turn the Plug and Play installation path into SYSTEM code execution.
The exploit begins when an attacker presents an emulated USB device to the target machine. The device is used to install software, which is then executed by Windows as part of the Plug and Play process. The researchers have demonstrated how this technique can be used to install a malicious service on a system, giving an authenticated low-privilege user SYSTEM code execution.
The vulnerability can also be triggered remotely over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled. In this scenario, the attacker presents a synthetic USB identity to Windows, causing it to follow the redirected device-installation path.
Microsoft has acknowledged that redirection is not allowed by default on Remote Desktop servers but notes that administrators can configure device-installation restrictions using the built-in policies. However, the researchers point out that the physical chain of events requires an attacker to present an emulated USB device to the target machine, which adds a level of complexity and risk.
The discovery has significant implications for enterprise security, particularly in light of the fact that the vulnerability can be exploited even on fully updated Windows 11 systems. The researchers emphasize that the technique was demonstrated using a fully updated system but notes that this should not be generalized to untested Windows versions.
In response to this vulnerability, Microsoft has reminded administrators that remote USB redirection is only allowed by default when it is explicitly configured as such. The company also stresses the importance of keeping software up-to-date and enforcing strict security policies to minimize the risk of exploitation.
The discovery serves as a reminder of the ongoing cat-and-mouse game between cybersecurity professionals and malicious actors. As new vulnerabilities are discovered, enterprises must remain vigilant and proactive in their efforts to stay secure.
Related Information:
https://www.ethicalhackingnews.com/articles/Plugging-into-Peril-A-Vulnerability-in-Windows-Plug-and-Play-Enables-Full-System-Takeover-ehn.shtml
https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
Published: Tue Aug 11 07:01:28 2026 by llama3.2 3B Q4_K_M