{"id":2316,"date":"2026-08-11T11:12:14","date_gmt":"2026-08-11T11:12:14","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2316"},"modified":"2026-08-11T11:12:14","modified_gmt":"2026-08-11T11:12:14","slug":"researchers-turn-usb-auto-install-into-a-full-system-takeover-on-windows-11","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2316","title":{"rendered":"Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 11, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIoEoCsvghUx_eKGXl-WAFq7pyoOLwg_Sk9a5Ne8vX1Cb7l_DOib3wtO_5NwoogbHqFvU_VWJZd3ceL5ftpWOX5qNx5HNJCmD4_RR7GaiExk0ph2F3sp5eKPthiuTcmnDlJQyvUdkTMfxBUsIlXp_I9-qkSi4zxwVnLPb9bG-T3zFC7oFCI1Mps4VJf1s\/s1700-e365\/pnp.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.<\/p>\n<p>The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default.<\/p>\n<p>Security researchers Alejandro Hernando and Borja Martinez described the technique in \u00ab<strong>Plug And Pwn: Weaponizing Windows PnP Auto-Install<\/strong>,\u00bb research prepared for DEF CON 34.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>They built tooling to emulate arbitrary USB devices and said that, under the required conditions, an unprivileged user can turn the PnP installation path into SYSTEM code execution. Microsoft&#8217;s own driver documentation describes the underlying selection step: Windows receives hardware and compatible IDs for a device and uses them to find a matching driver package.<\/p>\n<p>According to the <a href=\"https:\/\/plugandpwn.com\/\" target=\"_blank\">researchers<\/a>, the physical chain starts by emulating a Sierra Wireless device so Windows installs SwiService.exe, a SYSTEM service exposing a SetDNS primitive. They use it to redirect DNS, then emulate a Sony FeliCa reader whose co-installer retrieves configuration files over plaintext HTTP and derives local filenames from URL paths.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhEGRaLy42VSUXJSxCyQIvO1KtNM6g9BGsaVVQQ29zHB3211kbm_vS7NSxuP3P2e6JqjssuLGXILS6M7a8TQm4pHkfqVqxxKrar_MMammo8MCRM9OCNYiqP3a_m5-P-8s67mOHt3IP_b0r4jIIwU5E1q79lgd5OL8V7_m5eaEB5z9Jl2vUiM8F5rjBdcpw\/s1700-e365\/pic-1.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhEGRaLy42VSUXJSxCyQIvO1KtNM6g9BGsaVVQQ29zHB3211kbm_vS7NSxuP3P2e6JqjssuLGXILS6M7a8TQm4pHkfqVqxxKrar_MMammo8MCRM9OCNYiqP3a_m5-P-8s67mOHt3IP_b0r4jIIwU5E1q79lgd5OL8V7_m5eaEB5z9Jl2vUiM8F5rjBdcpw\/s1700-e365\/pic-1.gif\" alt=\"\" border=\"0\" data-original-height=\"720\" data-original-width=\"1280\"\/><\/a><\/div>\n<p>The researchers say a path-traversal flaw lets them place a DLL in System32; reconnecting the Sierra device then loads the planted DLL and yields SYSTEM. Their disclosed demonstration used a fully updated Windows 11 system, so the result should not be generalized to an untested Windows version range.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The remote variant replaces the physical device with synthetic USB traffic over RDP. The researchers&#8217; Python client forges a USB identity and presents a phantom Intel RealSense device, causing Windows to follow the redirected device-installation path.<\/p>\n<p>They say the resulting RealSense software can be abused through a CRYPTBASE.dll search-order hijack from a user-writable installation directory, giving the authenticated low-privilege user SYSTEM code execution. Microsoft separately <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/virtual-desktop\/redirection-configure-usb\" target=\"_blank\">documents<\/a> that redirected low-level USB peripherals use the same driver-installation process as a physical Windows computer.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhl7OdtjjB84PsIJKyR5HeL5HeYxeLfmH2ZfgFyGzJClRRAjEbUb0mtzqAW24pbIwyrRzd9l1Uow0Y5NdOP_alxtUR6LBpNi9nGdn68vVUNiuitW2yAweLwgu-3l3zrV176CDH1f6yh_soVUOquHmPSU4LeN1ZpVSSmkE9s_VY_FN9ZYAkxavorgs7uz48\/s1700-e365\/pic-2.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhl7OdtjjB84PsIJKyR5HeL5HeYxeLfmH2ZfgFyGzJClRRAjEbUb0mtzqAW24pbIwyrRzd9l1Uow0Y5NdOP_alxtUR6LBpNi9nGdn68vVUNiuitW2yAweLwgu-3l3zrV176CDH1f6yh_soVUOquHmPSU4LeN1ZpVSSmkE9s_VY_FN9ZYAkxavorgs7uz48\/s1700-e365\/pic-2.gif\" alt=\"\" border=\"0\" data-original-height=\"720\" data-original-width=\"1280\"\/><\/a><\/div>\n<p>The remote path is configuration-dependent, not a default Windows exposure. <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/client-management\/mdm\/policy-csp-admx-terminalserver\" target=\"_blank\">Microsoft says<\/a> Remote Desktop Services does not allow supported Plug and Play and RemoteFX USB redirection by default, and its USB-redirection guidance requires Plug and Play redirection to be enabled before low-level USB forwarding works.<\/p>\n<p>Administrators that do not need the feature can leave it disabled. Microsoft also provides <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/client-management\/mdm\/policy-csp-deviceinstallation\" target=\"_blank\">device-installation restrictions<\/a> that can allow or block devices by hardware or compatible ID, device-instance ID, and setup class; on a Remote Desktop server, those policies can also affect redirected devices.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The physical chain has its own precondition: an attacker has to be able to present an emulated USB device to the target machine.<\/p>\n<p>The research demonstrates abuse of a legitimate privileged installation path combined with weaknesses in signed third-party packages. The vendor-specific Sierra, Sony, and Intel exploit mechanics remain researcher findings and should stay attributed unless matching vendor material independently confirms them.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Aug 11, 2026Vulnerability \/ Enterprise Security Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2317,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2355,753,605,1045,754,2317,277,307],"class_list":["post-2316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-autoinstall","tag-full","tag-researchers","tag-system","tag-takeover","tag-turn","tag-usb","tag-windows"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2316"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2316\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2317"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}