PoC public Windows mobile Sierra Wireless privilege-escalation
Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM
CVE Tools coverage
Researchers Alejandro Hernando and Borja Martínez presented a new attack class called Plug and Pwn at DEF CON 34, demonstrating how Windows can be tricked into installing malicious software with SYSTEM privileges simply by plugging in a device. By emulating specific hardware identifiers using the FaceDancer framework, attackers forced Windows Update to automatically download and execute signed vendor components that contain exploitable vulnerabilities. This method allows for privilege escalation without user interaction or an active login session, effectively bypassing standard security prompts.