CyberSecurity News
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
AI summary
Researchers have found a way to exploit Windows Plug and Play to gain full SYSTEM access on a Windows 11 machine. This is done by abusing the feature to fetch and execute privileged installation components for an emulated USB device. The vulnerability can be triggered without physical hardware when certain conditions are met, such as over Remote Desktop with specific settings enabled. Microsoft is aware of the issue. The exploit allows for the execution of signed vendor software, which can be chained to achieve SYSTEM access. This can occur even on a fully updated Windows 11 machine.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

