blackhatnews.tokyo • 9m
Microsoft Windows 'Plug and Pwn': Hardware-Driven SYSTEM Privilege Escalation
Researchers Alejandro Hernando and Borja Martinez have identified a "Plug and Pwn" exploit chain targeting the Microsoft Windows Plug and Play (PnP) subsystem to achieve SYSTEM-level privileges on updated Windows 11 systems. The attack utilizes emulated USB device descriptors to trigger the installation of legitimate, signed third-party vendor software, which is then coerced into executing arbitrary code. This vulnerability extends beyond physical access via Remote Desktop Protocol (RDP) USB redirection, allowing for remote privilege escalation. The exploit effectively bypasses Driver Signature Enforcement (DSE) and Virtualization-Based Security (VBS) by leveraging the inherent trust placed in signed vendor binaries.