Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Dark bordered beauty moth found in Northumberland after 70 years
    • Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage
    • Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee
    • Hot topic: why is Burnham so reluctant to talk about the climate crisis? | Andy Burnham
    • Acer Promo Codes: 40% Off
    • Create a Reasoning-Focused LLM: A Practical Guide to Streaming, Curating, and Fine-Tuning the SupraLabs Reasoning Corpus
    • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
    • Morgan Stanley’s Bitcoin ETF drew $371 million of share contributions while Bitcoin erased $66.8 million
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Vulnerability / Enterprise Security

    Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.

    The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default.

    Security researchers Alejandro Hernando and Borja Martinez described the technique in “Plug And Pwn: Weaponizing Windows PnP Auto-Install,” research prepared for DEF CON 34.

    Cybersecurity

    They built tooling to emulate arbitrary USB devices and said that, under the required conditions, an unprivileged user can turn the PnP installation path into SYSTEM code execution. Microsoft’s own driver documentation describes the underlying selection step: Windows receives hardware and compatible IDs for a device and uses them to find a matching driver package.

    According to the researchers, the physical chain starts by emulating a Sierra Wireless device so Windows installs SwiService.exe, a SYSTEM service exposing a SetDNS primitive. They use it to redirect DNS, then emulate a Sony FeliCa reader whose co-installer retrieves configuration files over plaintext HTTP and derives local filenames from URL paths.

    The researchers say a path-traversal flaw lets them place a DLL in System32; reconnecting the Sierra device then loads the planted DLL and yields SYSTEM. Their disclosed demonstration used a fully updated Windows 11 system, so the result should not be generalized to an untested Windows version range.

    The remote variant replaces the physical device with synthetic USB traffic over RDP. The researchers’ Python client forges a USB identity and presents a phantom Intel RealSense device, causing Windows to follow the redirected device-installation path.

    They say the resulting RealSense software can be abused through a CRYPTBASE.dll search-order hijack from a user-writable installation directory, giving the authenticated low-privilege user SYSTEM code execution. Microsoft separately documents that redirected low-level USB peripherals use the same driver-installation process as a physical Windows computer.

    The remote path is configuration-dependent, not a default Windows exposure. Microsoft says Remote Desktop Services does not allow supported Plug and Play and RemoteFX USB redirection by default, and its USB-redirection guidance requires Plug and Play redirection to be enabled before low-level USB forwarding works.

    Administrators that do not need the feature can leave it disabled. Microsoft also provides device-installation restrictions that can allow or block devices by hardware or compatible ID, device-instance ID, and setup class; on a Remote Desktop server, those policies can also affect redirected devices.

    Cybersecurity

    The physical chain has its own precondition: an attacker has to be able to present an emulated USB device to the target machine.

    The research demonstrates abuse of a legitimate privileged installation path combined with weaknesses in signed third-party packages. The vendor-specific Sierra, Sony, and Intel exploit mechanics remain researcher findings and should stay attributed unless matching vendor material independently confirms them.

    AutoInstall Full researchers System takeover Turn USB Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026

    Hot topic: why is Burnham so reluctant to talk about the climate crisis? | Andy Burnham

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.