<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rdp on CuraSec</title><link>https://curasec.metacog.co.kr/tags/rdp/</link><description>Recent content in Rdp on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 11:54:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/rdp/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows PnP USB Emulation Chained to SYSTEM Privilege Escalation on Win11</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-researchers-turn-usb-auto-install-into-a-full-system-takeove/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-researchers-turn-usb-auto-install-into-a-full-system-takeove/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The RDP USB-redirection vector means physical access is not required, making this relevant to any enterprise RDP deployment on Windows 11. No patch or KEV yet, but audit Group Policy now to restrict or disable PnP/USB redirection over Remote Desktop where it isn&amp;rsquo;t operationally required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or active exploitation are confirmed, but the technique produces detectable PnP driver installation events tied to RDP sessions; queue a detection rule for unexpected signed-driver installs initiated from RDP-redirected device paths as a hunting lead.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Research-stage local privilege escalation against fully patched Windows 11; no active exploitation or regulatory trigger yet — file for awareness and revisit if Microsoft issues a patch or exploitation reports emerge.&lt;/li>
&lt;/ul></description></item></channel></rss>