Researchers Demonstrate Windows 11 USB Plug and Play Privilege Escalation Attack

Two security researchers showed how Windows 11's Plug and Play service can be exploited via USB to gain full SYSTEM-level access without any user clicks.

Plugging in a USB device can silently hand an attacker the highest level of Windows privileges — that is the core finding of a research project called 'Plug & Pwn,' presented at DEF CON 34. Security researchers Alejandro Hernando (known online as 0xedh) and Borja Martínez demonstrated that Windows 11's built-in Plug and Play service can be exploited to achieve SYSTEM-level privilege escalation, the most powerful access tier on a Windows machine. The attack requires no clicks or interaction from the target user beyond a USB device being connected. The researchers also examined related attack surfaces including USB identity spoofing, RDP USB redirection, and primitives introduced by third-party vendor software, according to their published research archive. The findings were disclosed as part of DEF CON 34, one of the largest and most prominent security research conferences, lending them significant visibility within the cybersecurity community. Details on whether Microsoft has been notified or has issued a patch are not specified in the available sources.

Why it matters

A zero-click, SYSTEM-level privilege escalation in a widely used operating system represents a high-severity risk, particularly in environments where physical USB access is possible, such as shared workstations or unattended machines. The attack's reliance on a core Windows service means the exposure is broad across Windows 11 installations.

What's next

It is not yet clear from available sources whether Microsoft has acknowledged the vulnerability or issued a patch, making that the key development to watch.

Key facts

Bias & framing notes

All three sources originate from the same outlet (IT Security News) or the researchers' own project page, providing no independent corroboration. The IT Security News headlines lean toward dramatic framing ('Plug & Pwn,' 'Zero Clicks'), while the researchers' own archive uses dry academic language. Neither Microsoft's response nor patch status is addressed in any source, and the articles appear truncated, limiting factual depth.

NewsClear — neutral news & congressional tracking · Bill of the Week