Fake USB and RDP Devices Can Grant Attackers SYSTEM Privileges on Windows
Security researchers have demonstrated a technique called 'Plug and Pwn' that exploits Windows Plug and Play to gain SYSTEM-level privileges by connecting fake or virtual USB devices. The attack works by tricking Windows into recognizing spoofed hardware — such as a Sierra Wireless or Sony FeliCa device — prompting automatic signed driver downloads from Windows Update and installation with SYSTEM privileges. A second attack chain abuses RDP USB redirection to deliver a crafted virtual device descriptor, exploiting Intel RealSense driver co-installers to execute malicious code without physical access. Neither user login nor UAC approval is required, making the attack appear as routine device setup behavior to the operating system. Mitigations include disabling RDP PnP redirection, enforcing device installation restrictions by Hardware ID, blocking Windows Update driver downloads, and applying vulnerable driver blocklists.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in