Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
ID: 0217553c-0c55-58c2-8224-92e0269e6f5a
STIX ID: report--0217553c-0c55-58c2-8224-92e0269e6f5a
Feed Name: Bleeping Computer
Security researchers presented "Plug and Pwn", a set of attacks that exploit Windows Plug and Play device installation to cause the OS to download and execute signed vendor drivers and co-installers as NT AUTHORITY\SYSTEM; demonstrations include USB device emulation (FaceDancer) and an RDP USB-redirection "NoPlug & Pwn" that can achieve SYSTEM privileges without user interaction. The report shows practical chains (e.g., Sierra Wireless + Sony FeliCa, Intel RealSense via RDP) against updated Windows systems, notes mitigations like the DisableCoInstallers registry key and device allow-lists, and warns these measures reduce but do not eliminate the attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
