[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRCJPo8LdLaUoS9VmzjrnB2_bxch18malfg5G9sXOhrY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"e6ed8a13-f9b6-4fa4-8d2c-2606ac1bfebf","fake-usb-devices-exploit-windows-plug-and-play-for-system-level-privilege-escalation","34ab902e-b9bb-42de-ace6-257f069b75d9","Fake USB Devices Exploit Windows Plug and Play for SYSTEM-Level Privilege Escalation","The 'Plug and Pwn' attack abuses Windows' built-in Plug and Play mechanism, which automatically installs vendor-signed driver packages — some of which contain exploitable components — without sufficient privilege controls. Because Windows trusts signed packages implicitly, attackers can emulate USB devices or leverage RDP to trigger installations that escalate privileges to SYSTEM level, requiring little to no user interaction. This matters because SYSTEM access represents the highest privilege tier on a Windows host, enabling full compromise without ever exploiting a traditional vulnerability in Windows itself. The attack highlights how trusted automation features and implicit trust in signed software can become a significant attack surface when not properly governed.","**Immediate actions:**\n- Audit and restrict which USB device classes are permitted to auto-install via Group Policy (e.g., `USBSTOR`, HID, network adapters).\n- Disable or restrict Plug and Play driver installation for non-administrator users using the `Prevent installation of devices not described by other policy settings` GPO.\n- Block inbound RDP from untrusted networks at the perimeter firewall to reduce remote exploitation vectors.\n\n**Long-term improvements:**\n- Implement an allowlist of approved, vetted driver packages and enforce it through Windows Defender Application Control (WDAC) or AppLocker policies.\n- Regularly audit third-party vendor software bundled with signed driver packages for known vulnerable components.\n- Apply the principle of least privilege so that even if Plug and Play triggers an install, the process cannot escalate to SYSTEM without additional controls.\n\n**Detection measures:**\n- Monitor Windows Event Logs (Event IDs 20001, 20003, 7045) for unexpected driver and service installations, especially outside of change windows.\n- Deploy endpoint detection tools that alert on new services or processes spawning at SYSTEM privilege from device installation paths.\n- Implement USB device inventory and anomaly detection to flag emulated or unexpected device identifiers on endpoints.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 18: Penetration Testing","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","NIST SP 800-53 AU-12: Audit Record Generation","NIST CSF PR.AC-4: Access Permissions and Authorizations","NIST CSF DE.CM-3: Personnel Activity Monitoring","Microsoft Security Baseline: Device Installation Restrictions via Group Policy","GDPR Article 32: Security of Processing (for environments handling personal data)","published","2026-08-12T18:20:41.838881+00:00","2026-08-12T18:20:41.524+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fplug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access\u002F","plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access-72e2ca","Plug and Pwn attack uses fake USB devices for Windows SYSTEM access",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]