By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Windows 11 USB Auto-Install Vulnerable to SYSTEM Takeover

Researchers have identified a critical vulnerability in Windows 11's Plug and Play (PnP) feature that allows for a full system takeover, granting SYSTEM access to an attacker. This exploit leverages the PnP mechanism, which is designed to automatically detect and install drivers and software for connected hardware. The researchers demonstrated that by emulating a USB device, they could trick Windows into fetching and executing signed vendor software. This signed software, when combined with privileged installation components, can be chained to achieve SYSTEM-level privileges on a fully updated Windows 11 machine. The exploit does not require administrator privileges to initiate the attack, as it exploits a trust relationship inherent in the PnP process. The researchers detailed their findings in a technical disclosure, outlining the specific steps and components involved in the attack chain. They explained that the PnP process, when a new hardware device is connected, queries for and installs appropriate drivers and associated software. By crafting a malicious USB device that emulates a specific type of hardware, an attacker can influence this process. The system then attempts to find and install the necessary software, which can be manipulated to include malicious code. This malicious code, once executed with the elevated privileges granted by the PnP installation process, can then perform any action on the system, including installing malware, stealing data, or disabling security features. A particularly concerning aspect of this vulnerability is its potential for remote exploitation. The same PnP path can be triggered over a Remote Desktop connection, even without physical access to the machine. This is possible when features like Plug and Play support or low-level USB redirection are enabled within the Remote Desktop session. In such scenarios, the remote system's PnP mechanism can be targeted, effectively bypassing the need for physical proximity. Microsoft has acknowledged the vulnerability and is working on a solution. The company stated that they are aware of the issue and are developing patches to address it. The researchers have provided detailed technical information to Microsoft to aid in the development of these fixes. The implications of this vulnerability are significant, as it affects a core feature of the Windows operating system that is widely used across millions of devices. The ability to gain SYSTEM access remotely and without prior administrator privileges makes it a potent tool for cybercriminals. Users are advised to remain vigilant and apply security updates as soon as they become available. The researchers emphasized the importance of secure hardware and software integration, highlighting how seemingly innocuous features can harbor significant security risks if not properly secured. The exploit underscores the ongoing challenges in securing complex operating systems against sophisticated attack vectors that target fundamental functionalities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.