Skip to main content

Tag: plug and pwn

2 articles

Laptop on a plain surface with a partially inserted USB device.

Windows Plug and Play Feature Exploited for SYSTEM Access via Fake USB Devices

Imagine a scenario where hackers can gain SYSTEM access to a Windows computer without needing a single click or logged-in user - and even exploit it remotely over RDP with no hardware involved. Researchers have just revealed a chilling new class of attacks, dubbed "Plug and Pwn", that takes advantage of Windows' Plug and Play feature to execute malicious software with alarming ease.

Analyst 207
Laptop on a workbench with USB device plugged in, surrounded by security research equipment.

Researchers Expose Windows 11 Vulnerability in USB Auto-Install Feature

Security researchers have uncovered a vulnerability in Windows 11's USB auto-install feature, allowing an unprivileged user to execute SYSTEM-level code on a fully updated machine. This clever hack, dubbed "Plug And Pwn," exploits the Plug and Play auto-install process to gain elevated access.

Analyst 207