Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
![]()

