Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
USB Exploit Enables SYSTEM Access on Windows 11

USB Exploit Enables SYSTEM Access on Windows 11

Posted on August 11, 2026 By CWS

Security experts have unveiled a novel method to gain SYSTEM-level access on Windows 11 via USB Plug and Play mechanisms. This vulnerability allows signed vendor software for emulated USB devices to execute privileged installation components, leading to a full SYSTEM takeover on an up-to-date system.

Exploiting Plug and Play on Windows

The researchers, Alejandro Hernando and Borja Martinez, presented their findings at DEF CON 34 under the title ‘Plug And Pwn: Weaponizing Windows PnP Auto-Install’. They demonstrated how an unprivileged user can transform the Plug and Play installation path into SYSTEM code execution by emulating arbitrary USB devices.

Through their method, a Sierra Wireless device is emulated, triggering Windows to install SwiService.exe, a SYSTEM service. This service allows DNS redirection, which is further manipulated by emulating a Sony FeliCa reader. The reader’s co-installer retrieves configuration files over unsecured HTTP, which can be used to introduce a DLL into the System32 directory, ultimately enabling SYSTEM access.

Remote Exploitation via RDP

The vulnerability is not limited to physical USB devices. By utilizing Remote Desktop Protocol (RDP), the same exploit can be replicated with synthetic USB traffic. A Python client simulates a phantom Intel RealSense device, prompting Windows to engage in a redirected installation path.

This remote variant relies on configuration settings, as Microsoft does not enable Plug and Play redirection by default in RDP. Nevertheless, if enabled, it can lead to SYSTEM code execution by exploiting a CRYPTBASE.dll search-order hijack from a writable installation directory.

Security Implications and Recommendations

The research highlights significant security concerns regarding the use of legitimate installation paths and third-party vendor packages. Microsoft acknowledges that Remote Desktop Services do not support Plug and Play redirection by default and has issued guidance on USB redirection configurations.

For enterprises, it is crucial to disable any unnecessary USB redirection features and implement device-installation restrictions to prevent unauthorized access. This includes controlling device permissions by hardware ID, compatible ID, and setup class, particularly on Remote Desktop servers.

The findings underscore the importance of staying vigilant against potential vulnerabilities and ensuring robust security measures are in place to protect against sophisticated attacks.

The Hacker News Tags:Cybersecurity, DEF CON, device redirection, DLL hijacking, emulated USB devices, enterprise security, Microsoft, Plug and Play, PnP attack, RDP, remote desktop, security vulnerability, SYSTEM access, USB exploit, Windows 11

Post navigation

Previous Post: CISA Alerts on Exploited SonicWall Vulnerabilities
Next Post: AI Chat Stealing Extension Reappears in Chrome Store

Related Posts

AI-Driven Ransomware Attack Exploits Langflow Vulnerability AI-Driven Ransomware Attack Exploits Langflow Vulnerability The Hacker News
Google Gemini Vulnerability Exposed by Notifications Google Gemini Vulnerability Exposed by Notifications The Hacker News
SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics The Hacker News
Critical Docker Vulnerability Allows Host Access Critical Docker Vulnerability Allows Host Access The Hacker News
Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network The Hacker News
Chinese Hacker Extradited to U.S. for COVID Cyberattacks Chinese Hacker Extradited to U.S. for COVID Cyberattacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Horizon3 Boosts Partner Growth with $20M Investment
  • Corma Secures $60M to Enhance Cybersecurity with AI
  • Vulnerable SIM Cards Threaten Cellular IoT Security
  • Ghostjacking Threat: AI Coding Agents at Risk
  • AI Chat Stealing Extension Reappears in Chrome Store

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Horizon3 Boosts Partner Growth with $20M Investment
  • Corma Secures $60M to Enhance Cybersecurity with AI
  • Vulnerable SIM Cards Threaten Cellular IoT Security
  • Ghostjacking Threat: AI Coding Agents at Risk
  • AI Chat Stealing Extension Reappears in Chrome Store

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark