View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Plug & Pwn chains Windows PnP installs into SYSTEM access

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Plug & Pwn chains Windows PnP installs into SYSTEM access Researchers demonstrated Plug & Pwn chains that turn Windows PnP driver installation into SYSTEM execution.
    • Fully updated Windows 11 systems are affected, including RDP and VDI environments with USB redirection enabled.
    • Windows Plug and Play can automatically install signed vendor packages containing insecure services, co-installers, and privileged components.
    • Researchers chained emulated Sierra Wireless and Sony FeliCa devices to redirect DNS, write a malicious DLL as SYSTEM, and load it before logon.
    • A remote variant forges Intel RealSense USB descriptors over RDP; a user-writable installer directory enables CRYPTBASE.dll sideloading as SYSTEM.
    • Additional Wacom and Atheros package weaknesses register a malicious print-monitor DLL that the Windows Print Spooler loads as SYSTEM. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ“‹ ADVISORIES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-73294 โ€” CVSS 9.9 โ€” Semaphore U: OS Command InjectionSemaphore UI is a web interface for managing...
  • CVE-2026-64639 โ€” CVSS 9.3 โ€” Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and...
  • CVE-2026-73293 โ€” CVSS 8.8 โ€” Semaphore UI: Manager-to-owner privilege escalation via custom-role slug coll...
  • CVE-2026-65941 โ€” CVSS 8.8 โ€” WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code ...
  • CVE-2026-15803 โ€” CVSS 8.7 โ€” In Eclipse RDF4J, several XML parser entry points do not fully restrict XML E...
  • CVE-2026-73325 โ€” CVSS 8.4 โ€” Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserial...
  • CVE-2026-73292 โ€” CVSS 8.3 โ€” Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token ...
  • CVE-2026-67260 โ€” CVSS 7.3 โ€” Apache Airflow: DAG-author remote code execution on the Scheduler via awaitin...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check