Utopia Tech
SecurityAI-assisted1 min read

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Security researchers have demonstrated a critical vulnerability in Windows 11's Plug and Play functionality that allows attackers to achieve SYSTEM-level access by exploiting the automatic installation process for emulated USB devices. The attack leverages signed vendor software fetched through PnP mechanisms and can be executed remotely via Remote Desktop when USB redirection is enabled, affectin

UT

Utopia Tech

August 11, 2026 · 1 min read

Share

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content