A newly disclosed "Plug & Pwn" attack chain exploits Windows' Plug and Play (PnP) driver installation process to execute unauthorized code as SYSTEM This article explores plug pwn exploits. . This technique leverages the automatic resolution of device hardware identifiers, enabling an attacker to bypass standard security measures without requiring administrator rights, user interaction, or physical access to USB devices.
The core vulnerability lies in how PnP integrates trusted software packages into the system, allowing attackers to install potentially insecure drivers without elevated privileges. New Plug & Pwn Exploits Windows' Vulnerable Device-Installation Mechanism In the "Plug & Pwn" demonstration, an attack machine running Linux uses FaceDancer hardware to impersonate Sierra Wireless and Sony devices on a fully patched Windows 11 system with no active user session.
Following this, the chain emulates a Sony FeliCa device, using its signed co-installer to fetch configuration files over unsecured HTTP without proper URL filtering or handling of backslashes and traversal sequences. The Atheros service introduces a crucial missing functionality by reading user-configured files and modifying privileged registry entries. Organizations should limit USB device installations, disable RDP USB redirection, inventory legacy driver packages, and monitor for unexpected driver installs, print-monitor registration, DNS changes, and SYSTEM services interacting with users.
Utilize in-browser data inspection from ANY.RUN to detect, investigate, and respond swiftly, ensuring a stronger SOC and reduced Mean Time To Remedy (MTTR).












