importantSYS.SOURCE: The Hacker News• 2026-08-11T16:18:26+05:30
Exploiting USB Auto-Install Vulnerability for SYSTEM Privilege Escalation in Windows 11
Researchers demonstrated a method to exploit Windows 11's USB Plug and Play auto-install functionality for SYSTEM-level privilege escalation through emulated devices. The attack requires physical access or RDP with USB redirection enabled, leveraging signed vendor software and path-traversal flaws.
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.
The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that
*** END OF TRANSMISSION ***