Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
AI Summary
Researchers Alejandro Hernando and Borja Martínez disclosed 'Plug and Pwn' attack techniques that exploit Windows Plug and Play to gain SYSTEM privileges by emulating malicious USB devices. The attacks abuse signed vendor software installed automatically by Windows during device enumeration, leveraging vulnerabilities in co-installers, services, or insecure update mechanisms. One variant, 'NoPlug & Pwn', abuses RDP USB redirection to perform the attack remotely without physical access. A demonstrated chain uses emulated Sierra Wireless and Sony FeliCa devices to manipulate DNS and hijack unencrypted downloads, ultimately achieving code execution as SYSTEM. Another RDP-based variant emulates an Intel RealSense camera to exploit DLL hijacking in a co-installer for privilege escalation.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | plugandpwn[.]com | Details → |