Plug and Pwn Provides Further Proof Windows’ Co-installers Are Dangerous
LG’s Monitor App Was Annoying, Plug and Pwn Is Dangerous
Microsoft was unimpressed with LG installing pop up ads for McAfee along with their LG Monitor App Installer when someone plugged in certain models of LG displays. Microsoft did not consider this a good reason to change the behaviour of Windows when a device was plugged in with what is called a co-installer; a feature which automatically downloads and installs vendor software and drivers when you plug a device in. If you notice the software and uninstall it, you only get a temporary reprieve as the co-installer will reinstall itself every time you unplug the device and plug it back in and likely on reboots as well.
LG’s behaviour annoyed Microsoft and users both, but it didn’t endanger your security. Plug and Pwn on the other hand does. It uses that same co-installer feature but instead of loading ads onto your computer, it abuses fact that in their infinite wisdom, Microsoft allows the vendor-supplied components to run as SYSTEM. This lets attackers add horrific things to a random USB device and when an unsuspecting victim plugs that device in, whatever payload is hiding on the device gets to silently run with the highest privilege going.
This has been abused in the past and will be in the future as long as this co-installer feature is enabled by default. Bleeping Computer covers a horrific list of infections that can spread with Plug and Pwn in this post.
Do not plug random USB devices into your machines and at least seriously consider disabling Windows’ co-installer feature with the steps found in that LG story link at the beginning of this post.
Windows supports a feature called co-installers, which automatically downloads and installs vendor software and drivers when a new USB device is inserted into a computer.
More Tech News From Around The Web
- AMD Instinct MI455X Deep Dive: CDNA 5 Marks The Next Era of Instinct @ ServeTheHome
- Lazarus hackers exploited Windows zero-day to target defense firms @ Bleeping Computer
- Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub @ The Register
- Google reveals 2026 hardware lineup: Pixel 11, Pixel Watch 5, and Pixel Tag @ Ars Technica
- DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi @ The Register
- Booksellers suspect AI firms are buying and then destroying rare books @ Ars Technica
- Deepfake hiccup unmasks suspected digital certificate fraudster @ The Register
- D-Link F518 5G Wi‑Fi 6 AX1800 Mobile Hotspot Review: All-Day Mobile Hotspot @ TweakTown


