ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

Windows 11 PnP and USB auto-install can be chained to SYSTEM takeover

Source headline: Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Threat level Critical
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Researchers show how Windows Plug and Play can be abused with an emulated USB device to fetch signed vendor software. They then chain the resulting installation components to gain SYSTEM-level control on fully patched Windows 11 systems. The same pathway can also be triggered over Remote Desktop when Plug and Play or low-level USB redirection is enabled. Because the workflow involves signed vendor content, it can help attackers blend into legitimate trust signals. Windows users should review USB redirection settings for remote sessions and restrict PnP/USB device access where possible.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#usb #windows11 #plugandplay #remotedesktop #system-takeover
Original reporting The Hacker News Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Open original source