Security researchers disclosed "Plug And Pwn," a technique that abuses Windows 11 Plug and Play auto-install behavior to gain NT AUTHORITY\SYSTEM code execution on fully updated systems without a kernel zero-day. By presenting a crafted or emulated USB device, the attack causes Windows to fetch signed vendor driver packages and run privileged installation components before user logon. The demonstrated chains relied on weaknesses in third-party software tied to devices from Sierra Wireless, Sony FeliCa, Intel RealSense, Wacom, and Atheros, including DNS manipulation, plaintext HTTP configuration retrieval, path traversal, arbitrary file write, privileged registry abuse, and DLL search-order hijacking or sideloading.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
The research also presented another demonstration combining Wacom and Atheros packages. According to the researchers, an Atheros service could perform attacker-influenced registry operations as SYSTEM and a Wacom service used a registry-controlled path that ultimately enabled a malicious print monitor DLL to be loaded by the Windows Print Spooler after reboot.
The researchers released a tool named PNP Simulate to inspect the Windows driver discovery and installation path without requiring physical hardware. The tool can create a root-enumerated device, assign USB hardware IDs, query package availability, and optionally force the device into the installation flow.
For the remote attack path, the researchers used a forged Intel RealSense device to trigger installation of software that could be abused through DLL search-order hijacking from a user-writable directory. They reported this gave an authenticated low-privilege user SYSTEM code execution when the relevant USB redirection features were enabled.
The researchers described a remote variant, called NoPlug and Pwn, for environments where RDP USB redirection is enabled, including some VDI deployments. In this scenario, a low-privilege remote user can send forged USB descriptors or synthetic USB traffic so the host enumerates a phantom device and enters the privileged Plug and Play installation path.
In a physical proof-of-concept, the researchers emulated a Sierra Wireless device to trigger installation of a SYSTEM service that let them alter DNS resolution, then emulated a Sony FeliCa device whose co-installer fetched configuration over plaintext HTTP. They used path traversal or arbitrary file write to place a DLL in System32, and reconnecting the Sierra device caused the DLL to load as SYSTEM, including before user logon.
Alejandro Hernando and Borja Martínez disclosed research on "Plug And Pwn," describing how Windows Plug and Play auto-install behavior can be abused to execute vendor-supplied installation components as NT AUTHORITY\SYSTEM on Windows 11 without a kernel zero-day. The work was prepared for DEF CON 34 and focused on chaining weaknesses in signed third-party packages rather than a universal Windows flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceplugandpwn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.