Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Summary

Researchers have discovered a method to achieve full SYSTEM takeover on Windows 11 by abusing the Plug and Play (PnP) feature. This vulnerability allows for the fetching and execution of signed vendor software, which can be chained to gain elevated privileges on a fully updated system.

IFF Assessment

FOE

This vulnerability allows attackers to gain SYSTEM-level access on Windows 11, posing a significant threat to defenders.

Severity

9.8 Critical (AI Estimated)

This vulnerability allows for a complete SYSTEM takeover on Windows 11, granting attackers full control over the affected machine. The attack can be initiated remotely without physical access, significantly increasing its exploitability and impact.

Defender Context

Defenders should be aware of this new attack vector that leverages a legitimate Windows feature for malicious purposes. This highlights the need for thorough auditing of device installations and ensuring that only trusted vendor software is allowed to execute, especially in remote access scenarios.

Read Full Story →