CVE Tools
Back to feed
PoC public Windows mobile Sierra Wireless privilege-escalation

Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM

Хакер (xakep.ru)·By Мария Нефёдова··3 min read
CVE Tools coverage

Researchers Alejandro Hernando and Borja Martínez presented a new attack class called Plug and Pwn at DEF CON 34, demonstrating how Windows can be tricked into installing malicious software with SYSTEM privileges simply by plugging in a device. By emulating specific hardware identifiers using the FaceDancer framework, attackers forced Windows Update to automatically download and execute signed vendor components that contain exploitable vulnerabilities. This method allows for privilege escalation without user interaction or an active login session, effectively bypassing standard security prompts.