Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks

Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITY\SYSTEM. The technique, published by researchers Alejandro Hernando and Borja Martínez, does not rely on a Windows kernel zero-day. Instead, it abuses the process Windows uses to detect hardware, find a matching vendor package, download it, and […]

This article has been indexed from Cyber Security News

Read the original article: