CVE Tools

Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM

Хакер (xakep.ru)By Мария Нефёдова

PoC publicWindows

Our summary

Researchers Alejandro Hernando and Borja Martínez presented a new attack class called Plug and Pwn at DEF CON 34, demonstrating how Windows can be tricked into installing malicious software with SYSTEM privileges simply by plugging in a device. By emulating specific hardware identifiers using the FaceDancer framework, attackers forced Windows Update to automatically download and execute signed vendor components that contain exploitable vulnerabilities. This method allows for privilege escalation without user interaction or an active login session, effectively bypassing standard security prompts.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store