OS SecurityBleeping Computer
7.8 — HIGH
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The Plug and Pwn attack exploits Windows' Plug and Play feature to install vulnerable software with SYSTEM privileges, allowing attackers to gain unauthorized access to the system. This attack can be performed remotely over RDP without physical USB hardware being connected.
⚙️Technical Details
💥Impact Assessment
Severity: High
Who Is at Risk
Users of Windows systems with Plug and Play feature enabled, particularly those in the finance, healthcare, and government sectors
🛡️Recommended Actions
1Enable UAC prompts for all software installations
2Regularly update Windows and installed software to patch vulnerabilities
3Disable RDP USB redirection when not in use
📦Affected Products
Qualcomm Qca6174Qualcomm Qca6174 FirmwareWindows systems with Plug and Play feature enabled
🔐NVD Verified DataVERIFIED
CVE-2019-10617 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected Products (CPE)
Qualcomm Qca6174Qualcomm Qca6174 Firmware
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
