Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Researchers exploited Windows Plug and Play to auto-install signed vendor software from an emulated USB device, chaining the process to achieve full SYSTEM access on a fully updated Windows 11 machine. The same attack vector can be triggered over Remote Desktop when USB redirection is enabled.
Researchers demonstrated a full SYSTEM takeover on a fully updated Windows 11 machine by abusing USB auto-install. They exploited Windows Plug and Play to fetch signed vendor software for an emulated USB device, then executed privileged installation components to escalate to SYSTEM-level access. The same attack chain works over Remote Desktop without physical hardware if Plug and Play or low-level USB redirection is enabled. Microsoft has acknowledged the issue.