Windows 11 PnP and USB auto-install can be chained to SYSTEM takeover
Source headline: Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Intelligence Summary
Researchers show how Windows Plug and Play can be abused with an emulated USB device to fetch signed vendor software. They then chain the resulting installation components to gain SYSTEM-level control on fully patched Windows 11 systems. The same pathway can also be triggered over Remote Desktop when Plug and Play or low-level USB redirection is enabled. Because the workflow involves signed vendor content, it can help attackers blend into legitimate trust signals. Windows users should review USB redirection settings for remote sessions and restrict PnP/USB device access where possible.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.