Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34. According to the researchers, the physical chain starts by emulating a Sierra Wireless device so Windows installs SwiService.exe, a SYSTEM service exposing a SetDNS primitive. Their disclosed demonstration used a fully updated Windows 11 system, so the result should not be generalized to an untested Windows version range. Microsoft separately documents that redirected low-level USB peripherals use the same driver-installation process as a physical Windows computer.