🔌 Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface
Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely — no physical USB device required.
Look at how this attack works and how Netlas can help map exposed RDP infrastructure.
👉 https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
Post #631
418