Researchers disclose 'Plug and Pwn' Windows attack that uses fake USB devices to gain SYSTEM access

Security researchers disclosed a new Windows attack called Plug and Pwn that can make a PC install vulnerable vendor software and give an attacker full SYSTEM-level control. The attack abuses Windows Plug and Play and co-installers, which can automatically fetch and run signed vendor packages as NT AUTHORITY\SYSTEM when new hardware is detected. The researchers said some attack chains need no user interaction or logged-in session, and one variant can be triggered remotely over Remote Desktop Protocol (RDP) without physical USB hardware.
Why it matters: This affects Windows systems because it turns normal device-detection behavior into a path for full machine compromise. Defenders should review device-installation policies, restrict automatic driver and co-installer installation where possible, and watch for unexpected hardware-install events and vendor package execution under SYSTEM.

Sources

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Lawrence Abrams 2026.08.12 100% relevant
This article establishes a distinct new Windows privilege-escalation story centered on the newly presented Plug and Pwn attack path rather than a previously tracked CVE-specific event.
← Back to all stories