Feed›OS Security›Plug and Pwn attack uses fake USB devices for Windows SYSTEM...
OS SecurityBleeping Computer
7.8 — HIGH

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

📅 12 August 2026 at 16:05 UTC📰 Bleeping ComputerView original source ↗
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

The Plug and Pwn attack exploits Windows' Plug and Play feature to install vulnerable software with SYSTEM privileges, allowing attackers to gain unauthorized access to the system. This attack can be performed remotely over RDP without physical USB hardware being connected.

⚙️Technical Details
💥Impact Assessment
Severity: High
Who Is at Risk
Users of Windows systems with Plug and Play feature enabled, particularly those in the finance, healthcare, and government sectors
🛡️Recommended Actions
1Enable UAC prompts for all software installations
2Regularly update Windows and installed software to patch vulnerabilities
3Disable RDP USB redirection when not in use
📦Affected Products
Qualcomm Qca6174Qualcomm Qca6174 FirmwareWindows systems with Plug and Play feature enabled
🔐NVD Verified DataVERIFIED
CVE-2019-10617 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products (CPE)
Qualcomm Qca6174Qualcomm Qca6174 Firmware

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed