DEF CON Reveals 'Plug and Pwn' Windows Privilege Escalation via Fake USB

evilsocket · x · 2026-08-13

Security researchers at DEF CON 34 disclosed the 'Plug and Pwn' attack, which abuses Windows Plug and Play features. By emulating USB devices, attackers can force Windows to automatically install vulnerable vendor drivers, gaining SYSTEM privileges. Some attacks require no user interaction or can be triggered remotely via RDP.

Original post →

More from Safety

Safety channel →