Close Menu
NCIJ Network NCIJ Network
    What's Hot

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026

    Farage’s by-election victory won’t stop questions about finances

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • North Korea fumes over upcoming US-South Korea military drills | Military News
    • The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO
    • Farage’s by-election victory won’t stop questions about finances
    • JPMorgan debanked Polymarket over regulatory concerns
    • Babbel Promo Code: Up to 65% Off in August 2026
    • Meet Needle 2: An Open 45M-Parameter Tool-Calling Model That Ships as a 14MB Binary and Runs a Full Session in 28MB of RAM
    • Hackers breach govt webmail while running parallel crypto fraud
    • Tether Finally Completes Independent Audit Of Reserves
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Vulnerability / Enterprise Security

    Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.

    The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default.

    Security researchers Alejandro Hernando and Borja Martinez described the technique in “Plug And Pwn: Weaponizing Windows PnP Auto-Install,” research prepared for DEF CON 34.

    Cybersecurity

    They built tooling to emulate arbitrary USB devices and said that, under the required conditions, an unprivileged user can turn the PnP installation path into SYSTEM code execution. Microsoft’s own driver documentation describes the underlying selection step: Windows receives hardware and compatible IDs for a device and uses them to find a matching driver package.

    According to the researchers, the physical chain starts by emulating a Sierra Wireless device so Windows installs SwiService.exe, a SYSTEM service exposing a SetDNS primitive. They use it to redirect DNS, then emulate a Sony FeliCa reader whose co-installer retrieves configuration files over plaintext HTTP and derives local filenames from URL paths.

    The researchers say a path-traversal flaw lets them place a DLL in System32; reconnecting the Sierra device then loads the planted DLL and yields SYSTEM. Their disclosed demonstration used a fully updated Windows 11 system, so the result should not be generalized to an untested Windows version range.

    The remote variant replaces the physical device with synthetic USB traffic over RDP. The researchers’ Python client forges a USB identity and presents a phantom Intel RealSense device, causing Windows to follow the redirected device-installation path.

    They say the resulting RealSense software can be abused through a CRYPTBASE.dll search-order hijack from a user-writable installation directory, giving the authenticated low-privilege user SYSTEM code execution. Microsoft separately documents that redirected low-level USB peripherals use the same driver-installation process as a physical Windows computer.

    The remote path is configuration-dependent, not a default Windows exposure. Microsoft says Remote Desktop Services does not allow supported Plug and Play and RemoteFX USB redirection by default, and its USB-redirection guidance requires Plug and Play redirection to be enabled before low-level USB forwarding works.

    Administrators that do not need the feature can leave it disabled. Microsoft also provides device-installation restrictions that can allow or block devices by hardware or compatible ID, device-instance ID, and setup class; on a Remote Desktop server, those policies can also affect redirected devices.

    Cybersecurity

    The physical chain has its own precondition: an attacker has to be able to present an emulated USB device to the target machine.

    The research demonstrates abuse of a legitimate privileged installation path combined with weaknesses in signed third-party packages. The vendor-specific Sierra, Sony, and Intel exploit mechanics remain researcher findings and should stay attributed unless matching vendor material independently confirms them.

    AutoInstall Full researchers System takeover Turn USB Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Meet Needle 2: An Open 45M-Parameter Tool-Calling Model That Ships as a 14MB Binary and Runs a Full Session in 28MB of RAM

    Hackers breach govt webmail while running parallel crypto fraud

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026

    Farage’s by-election victory won’t stop questions about finances

    August 14, 2026

    JPMorgan debanked Polymarket over regulatory concerns

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026

    Farage’s by-election victory won’t stop questions about finances

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.