Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITY\SYSTEM. The technique, published by researchers Alejandro Hernando and Borja Martínez, does not rely on a Windows kernel zero-day. Instead, it abuses the process Windows uses to detect hardware, find a matching vendor package, download it, and run installation components with SYSTEM rights. The researchers say the issue can be triggered when a USB device is connected to a Windows 11 computer, even when no user is signed in. An attacker can emulate a device identity with a FaceDancer. Windows resolves its driver package and starts vendor-supplied code in a privileged installation context. Their physical...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!