Never Plug In an Unknown USB Device
Click here to view/listen to our blogcast.
An unfamiliar USB drive found in a parking lot may look harmless. So might a promotional device handed out at an event or a cable left in a conference room. The safe response is simple: do not connect it to an organization-owned computer.
New security research shows why that rule must cover more than ordinary thumb drives. Researchers demonstrated “Plug and Pwn” attacks in which specially prepared hardware impersonates trusted USB devices. Windows then follows its normal Plug and Play process, installing matching drivers and vendor software. In some cases, that legitimate process can be turned into SYSTEM-level access, the highest privilege level in Windows.
How a Fake USB Device Can Fool Windows
Windows is designed to make hardware easy to use. When a new device is connected, Plug and Play identifies it, locates a matching driver package, and may install supporting vendor software. Much of this activity occurs automatically because Windows must configure hardware before an ordinary user can work with it.
According to BleepingComputer’s August 12 report, researchers Alejandro Hernando and Borja Martínez used programmable hardware to imitate several commercial USB devices. Their attack chains caused Windows to retrieve signed vendor packages containing components or weaknesses that could be abused.
One demonstration reportedly worked against a fully updated Windows 11 computer in about five minutes, with nobody logged in. The chain changed Domain Name System (DNS) settings, redirected an unencrypted download, placed a malicious file, and ultimately obtained a SYSTEM-level reverse shell.
They also demonstrated a remote version through Remote Desktop Protocol (RDP) USB redirection. Instead of physically inserting hardware, a custom RDP client supplied fake USB device information to a remote Windows host. That scenario matters to organizations using virtual desktops or remote systems where device redirection is enabled.
This does not mean every USB device is malicious. It demonstrates that trusted operating-system features and signed vendor software can still become links in an attack chain.
Why Removing Local Administrator Rights Still Matters
A standard user account would not have stopped every Plug and Pwn demonstration. Some of the reported chains reached SYSTEM through Windows’ privileged device-installation process, even without a logged-in user. Organizations therefore should not treat least privilege as their only USB defense.
However, routine users still should not operate as local administrators. Many malicious USB attacks rely on persuading someone to open a file, run a program, install software, or approve a change. Administrator access can turn one mistaken click into a much larger compromise. A standard account limits what ordinary activity can change and forces privileged work into a separate, controlled process.
This follows least privilege: give each person and process only the access needed for its job. NIST security controls treat privileged-account management, device restrictions, and removable-media controls as complementary protections.
What Organizations Should Do Now
USB security should combine policy, technology, monitoring, and employee judgment. Start with these priorities:
- Establish a clear rule that employees must never connect found, borrowed, promotional, or otherwise unknown USB devices, cables, or peripherals to organizational systems.
- Remove local administrator rights from routine user accounts. Provide a controlled method for approved installations and maintenance.
- Use device-installation restrictions or allow lists so approved hardware can function while unknown device types or hardware IDs are blocked. Microsoft documents device controls available through Windows, Microsoft Defender for Endpoint, Group Policy, and Intune.
- Review RDP and virtual desktop settings. Disable Plug and Play device redirection where the business does not need it.
- Keep Windows, drivers, endpoint protection, and vendor utilities patched. Signed software is not automatically risk-free.
- Train employees to hand suspicious devices to IT. Testing should occur only in an isolated environment using an approved process, never on a production workstation.
- Monitor device installation events and investigate unexpected drivers, services, DNS changes, or peripheral activity.
Some administrators may also evaluate disabling device co-installers, but the researchers cautioned that this setting would interrupt only part of the demonstrated attack surface. It should be considered one technical control within a broader device-management strategy.
How CDML Can Help
CDML can help organizations review local administrator access, create practical USB and peripheral policies, configure Microsoft Intune and Microsoft Defender controls, and assess RDP or virtual desktop redirection settings. We can also help establish monitoring, patching, employee security training, and incident-response procedures so suspicious device activity is reported and handled consistently.
The right configuration depends on how an organization uses scanners, printers, security keys, mobile devices, and specialized equipment. The goal is to approve what the organization needs and reduce exposure to everything else.
Final Thoughts
A USB connection is not automatically trustworthy just because the device looks familiar or Windows recognizes it. Plug and Pwn demonstrates how a small piece of hardware can trigger a privileged software chain before an employee realizes anything happened.
Teach users to stop before they plug in unknown devices, remove unnecessary administrator rights, and enforce device controls centrally. If you need help reviewing these protections, contact CDML Computer Services for a practical security assessment.
Stay safe. Stay informed. Stay compliant.

📞 Contact us here: https://cdml.com/contact/
📚 Read more on our blog: https://cdml.com/blog-2
📺 Listen to our blogcasts: https://www.youtube.com/@CDMLComputerServices


