Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
USB Exploit Enables SYSTEM Access on Windows 11

USB Exploit Enables SYSTEM Access on Windows 11

Posted on August 11, 2026 By CWS

Security experts have unveiled a novel method to gain SYSTEM-level access on Windows 11 via USB Plug and Play mechanisms. This vulnerability allows signed vendor software for emulated USB devices to execute privileged installation components, leading to a full SYSTEM takeover on an up-to-date system.

Exploiting Plug and Play on Windows

The researchers, Alejandro Hernando and Borja Martinez, presented their findings at DEF CON 34 under the title ‘Plug And Pwn: Weaponizing Windows PnP Auto-Install’. They demonstrated how an unprivileged user can transform the Plug and Play installation path into SYSTEM code execution by emulating arbitrary USB devices.

Through their method, a Sierra Wireless device is emulated, triggering Windows to install SwiService.exe, a SYSTEM service. This service allows DNS redirection, which is further manipulated by emulating a Sony FeliCa reader. The reader’s co-installer retrieves configuration files over unsecured HTTP, which can be used to introduce a DLL into the System32 directory, ultimately enabling SYSTEM access.

Remote Exploitation via RDP

The vulnerability is not limited to physical USB devices. By utilizing Remote Desktop Protocol (RDP), the same exploit can be replicated with synthetic USB traffic. A Python client simulates a phantom Intel RealSense device, prompting Windows to engage in a redirected installation path.

This remote variant relies on configuration settings, as Microsoft does not enable Plug and Play redirection by default in RDP. Nevertheless, if enabled, it can lead to SYSTEM code execution by exploiting a CRYPTBASE.dll search-order hijack from a writable installation directory.

Security Implications and Recommendations

The research highlights significant security concerns regarding the use of legitimate installation paths and third-party vendor packages. Microsoft acknowledges that Remote Desktop Services do not support Plug and Play redirection by default and has issued guidance on USB redirection configurations.

For enterprises, it is crucial to disable any unnecessary USB redirection features and implement device-installation restrictions to prevent unauthorized access. This includes controlling device permissions by hardware ID, compatible ID, and setup class, particularly on Remote Desktop servers.

The findings underscore the importance of staying vigilant against potential vulnerabilities and ensuring robust security measures are in place to protect against sophisticated attacks.

The Hacker News Tags:Cybersecurity, DEF CON, device redirection, DLL hijacking, emulated USB devices, enterprise security, Microsoft, Plug and Play, PnP attack, RDP, remote desktop, security vulnerability, SYSTEM access, USB exploit, Windows 11

Post navigation

Previous Post: CISA Alerts on Exploited SonicWall Vulnerabilities
Next Post: AI Chat Stealing Extension Reappears in Chrome Store

Related Posts

Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software The Hacker News
Critical Open VSX Bug Fixed in VS Code Extension Security Critical Open VSX Bug Fixed in VS Code Extension Security The Hacker News
New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft The Hacker News
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China The Hacker News
Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more The Hacker News
A walkthrough of the Google Workspace Password Manager A walkthrough of the Google Workspace Password Manager The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark