Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Summary
Researchers have discovered a method to achieve full SYSTEM takeover on Windows 11 by abusing the Plug and Play (PnP) feature. This vulnerability allows for the fetching and execution of signed vendor software, which can be chained to gain elevated privileges on a fully updated system.
IFF Assessment
This vulnerability allows attackers to gain SYSTEM-level access on Windows 11, posing a significant threat to defenders.
Severity
This vulnerability allows for a complete SYSTEM takeover on Windows 11, granting attackers full control over the affected machine. The attack can be initiated remotely without physical access, significantly increasing its exploitability and impact.
Defender Context
Defenders should be aware of this new attack vector that leverages a legitimate Windows feature for malicious purposes. This highlights the need for thorough auditing of device installations and ensuring that only trusted vendor software is allowed to execute, especially in remote access scenarios.