
New Plug & Pwn Attack Abuses Windows Plug and Play to Gain SYSTEM Privileges
A newly disclosed “Plug & Pwn,” is a set of attack chains that weaponize Windows Plug and Play (PnP) driver installation to execute vendor-supplied code as NT AUTHORITY\SYSTEM. Plugandpwn demonstrates how an attacker can abuse trusted device-driver packages delivered through Windows Update without administrator rights, user interaction, or, in certain scenarios, physical USB hardware. The […]
The post New Plug & Pwn Attack Abuses Windows Plug and Play to Gain SYSTEM Privileges appeared first on Cyber Security News.