We’re in 2026 and it is entirely possible for an attacker to hack into a Windows computer using a “simple” USB device. Hollywood screenwriters were right from the start, but we never listened.

The aim of this blog post is to provide practical guidance about the “Plug&Pwn” attack scenarios to help security professionals understand and mitigate the risks.

TL;DR – An attacker with physical access to a locked Windows computer can compromise it without user interaction by gaining arbitrary code execution as SYSTEM, using a USB device. There is no Windows update or security patch that protects against it, only configuration hardening can help prevent it. An attacker with authenticated RDP access to a Windows computer may escalate privileges remotely by emulating a USB device as well, under certain conditions.