Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Read full story on The Hacker News
Share
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
AI disclosure

Summary

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.