Fake USB Devices Can Trick Windows 11 Into Handing Over Full Control
Security researchers have demonstrated a serious weakness in Windows 11's Plug and Play system, the feature that automatically installs drivers when a USB device is connected. By emulating a USB device and tricking Windows into fetching signed vendor installation software, attackers were able to chain together privileged components and gain SYSTEM-level access — the highest level of control on a Windows machine — on a fully updated Windows 11 computer.
What makes this discovery particularly concerning is that physical access isn't required. The same technique can reportedly be triggered remotely over Remote Desktop connections where Plug and Play or low-level USB redirection features are enabled. This means an attacker with remote access to a session could potentially escalate their privileges without ever touching the target device.
Microsoft has been made aware of the issue, though full technical details and a patch timeline have not yet been confirmed. Until a fix is available, businesses using Remote Desktop should review whether USB redirection features are necessary and consider disabling them if not in active use.