New Plug & Pwn Attack Abuses Windows Plug and Play to Gain SYSTEM Privileges
Brief
A newly disclosed “Plug & Pwn,” is a set of attack chains that weaponize Windows Plug and Play (PnP) driver installation to execute vendor-supplied code as NT AUTHORITY\SYSTEM.
Plugandpwn demonstrates how an attacker can abuse trusted device-driver packages delivered through Windows Update without administrator rights, user interaction, or, in certain scenarios, physical USB hardware. The core issue is not a flaw in USB enumeration itself.
Instead, the researchers argue that Windows PnP becomes a privileged delivery mechanism when it automatically resolves a connected device’s hardware identifiers, downloads a matching signed driver package, and runs installation components as SYSTEM.
