CVE Tools
Back to feed
PoC public Windows privilege-escalation Microsoft auth-bypass

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

BleepingComputer·By Lawrence Abrams··7 min read
CVE Tools coverage

Security researchers have presented "Plug and Pwn" techniques at DEF CON 34 that exploit the Windows Plug and Play mechanism to achieve full SYSTEM privilege escalation. By emulating specific USB devices using hardware like FaceDancer, attackers can trick Windows into automatically installing signed vendor packages that contain exploitable weaknesses, bypassing User Account Control.

The demonstrations include both physical zero-click scenarios involving Sierra Wireless and Sony FeliCa drivers, as well as a remote variant, termed "NoPlug & Pwn," that leverages RDP USB redirection to target virtual desktop environments. While mitigations such as disabling co-installers reduce risk, the underlying attack surface persists, highlighting the need for stricter device installation policies on sensitive Windows systems.