BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Plug And Pwn: Weaponizing Windows PnP Auto-Install\n
    Tags: DEF CON Official Talk | Demo ðŸ’» | Exploit ðŸª²\n   When: Friday
 \, Aug 7\, 13:30 - 14:30 PDT\n   Where: LVCCW Level 1 Hall 3 904 (Main Tra
 ck 4) and DCTV-4 - [1]Map\n\n   Description:\n\n   Every time a USB device
  is plugged into a Windows machine\, the OS may\n   silently download a pa
 ckage from Microsoft and execute vendor code as\n   SYSTEM. No admin requi
 red. The package is signed\, so nothing looks\n   wrong.\n\n   We spent th
 e better part of a year mapping this attack surface. We\n   analyzed 7K pa
 ckages approx\, built tools to emulate arbitrary USB\n   devices without h
 ardware\, and found that the same kernel code path\n   fires when a USB de
 vice is redirected over RDP channels\, meaning a non\n   admin user can tr
 igger SYSTEM level code execution on the target\, with\n   no physical acc
 ess at all (under certain conditions).\n\n     * \n\n       How Windows Pn
 P search actually works\, the real kernel flow\, not\n       the MSDN summ
 ary.\n\n     * \n\n       How to make Windows believe any USB device is co
 nnected\, using\n       device emulation and composite device tricks that 
 bypass inbox\n       driver interception.\n\n     * \n\n       Why RDP USB
  redirection (MS-RDPEUSB / URBDRC) triggers the exact\n       same kernel 
 PnP path as a physical plug-in\, and what that means\n       for remote ex
 ploitation.\n\n     * \n\n       A WHQL-signed software that contains a hi
 dden debug backdoor\n       alowing execution as SYSTEM\, chainable with o
 ther vulnerabilities\n       for full user to SYSTEM escalation from a sta
 ndard account.\n\n     * \n\n       A forced installation leading to the c
 reation of a named pipe that\n       lets any authenticated network user r
 ewrite config on any machine.\n\n   Speakers:Alejandro "0xedh" Hernando\,B
 orja "borjmz" Martinez\n\n   SpeakerBio:  Alejandro "0xedh" Hernando\, Acc
 enture Spain\n\n   Alejandro Hernando is a red team operator and security 
 researcher at\n   Accenture Security's Hacking team in Spain\, with over a
  decade of\n   hands-on experience in offensive cybersecurity. Throughout 
 his career\,\n   he has assessed\, exploited\, and helped mitigate securit
 y\n   vulnerabilities across commercial and proprietary systems\, developi
 ng\n   PoC exploits\, offensive and defensive tooling\, and conducting dee
 p\n   security research. His approach combines applied research with real\
 n   world operational experience\, driven by a focus on continuous learnin
 g\n   and on sharpening both attack and defense strategies.\n\n   SpeakerB
 io:  Borja "borjmz" Martinez\, Accenture Spain\n\n   Borja MartÃnez is a r
 ed team operator and security researcher at\n   Accenture Security Hacking
  team in Spain\, where he focuses on\n   offensive security\, advanced adv
 ersary simulation and hardware\n   exploitation. A self-taught hacker with
  a deeply hands-on approach\, he\n   specializes in red team operations\, 
 penetration testing and low level\n   attack research including DMA attack
 s\, BIOS/UEFI exploitation\, and TPM\n   security.\n\n   '\n\n   1. #LVCCW
 _Level1_Hall3\n\n\n
DTEND:20260807T213000Z
DTSTART:20260807T203000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Plug And Pwn: Weaponizing Windows PnP Auto-Install
END:VEVENT
END:VCALENDAR
