Crypto Ticker:
sysadmin from Cyber Security News

Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks

Abinaya
Tuesday at 13:59
14 Views
0 Comments
Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks

Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITY\SYSTEM. The technique, published by researchers Alejandro Hernando and Borja Martínez, does not rely on a Windows kernel zero-day. Instead, it abuses the process Windows uses to detect hardware, find a matching vendor package, download it, and run installation components with SYSTEM rights. The researchers say the issue can be triggered when a USB device is connected to a Windows 11 computer, even when no user is signed in. An attacker can emulate a device identity with a FaceDancer. Windows resolves its driver package and starts vendor-supplied code in a privileged installation context. Their physical...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!