Threat Intelligence

Fake USB Devices Can Trick Windows 11 Into Handing Over Full Control

The Hacker News · 11 Aug 2026
Key Takeaway If your business uses Remote Desktop, review and disable unnecessary USB or Plug and Play redirection settings until Microsoft issues a fix.

Security researchers have demonstrated a serious weakness in Windows 11's Plug and Play system, the feature that automatically installs drivers when a USB device is connected. By emulating a USB device and tricking Windows into fetching signed vendor installation software, attackers were able to chain together privileged components and gain SYSTEM-level access — the highest level of control on a Windows machine — on a fully updated Windows 11 computer.

What makes this discovery particularly concerning is that physical access isn't required. The same technique can reportedly be triggered remotely over Remote Desktop connections where Plug and Play or low-level USB redirection features are enabled. This means an attacker with remote access to a session could potentially escalate their privileges without ever touching the target device.

Microsoft has been made aware of the issue, though full technical details and a patch timeline have not yet been confirmed. Until a fix is available, businesses using Remote Desktop should review whether USB redirection features are necessary and consider disabling them if not in active use.

Windows 11 Remote Desktop Privilege Escalation USB Security Microsoft

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.