Researchers unveiled “Plug and Pwn” attacks that abuse Windows Plug and Play and RDP USB redirection to force automatic installation of vulnerable vendor packages, enabling attackers to gain SYSTEM privileges. The demonstrations used emulated USB devices and affected software from Sierra Wireless, Sony FeliCa, Intel RealSense, Wacom, and Atheros, showing that even fully updated Windows systems can be exposed. #PlugandPwn #SierraWireless #SonyFeliCa #IntelRealSense #Wacom #Atheros
Keypoints
- Plug and Pwn abuses Windows Plug and Play to trigger automatic vendor software installation.
- The attack can lead to SYSTEM privileges without UAC prompts.
- Researchers used FaceDancer hardware to emulate USB devices and force driver matching.
- Some attack chains work with no user interaction, and one works remotely over RDP USB redirection.
- DisableCoInstallers helps, but device restrictions and PnP redirection blocking are also recommended.