Security researchers disclosed a new Windows attack called Plug and Pwn that can make a PC install vulnerable vendor software and give an attacker full SYSTEM-level control. The attack abuses Windows Plug and Play and co-installers, which can automatically fetch and run signed vendor packages as NT AUTHORITY\SYSTEM when new hardware is detected. The researchers said some attack chains need no user interaction or logged-in session, and one variant can be triggered remotely over Remote Desktop Protocol (RDP) without physical USB hardware.
Why it matters: This affects Windows systems because it turns normal device-detection behavior into a path for full machine compromise. Defenders should review device-installation policies, restrict automatic driver and co-installer installation where possible, and watch for unexpected hardware-install events and vendor package execution under SYSTEM.
Lawrence Abrams
2026.08.12
100% relevant
This article establishes a distinct new Windows privilege-escalation story centered on the newly presented Plug and Pwn attack path rather than a previously tracked CVE-specific event.
← Back to all stories