Windows privilege escalation via USB
@j0nh4t discovered that you can escalate from user to SYSTEM on an unlocked Windows machine just by plugging in a Razer mouse and clicking in the right places. At this meeting we’ll take a look at how the specific exploit works and more interestingly how it falls into a no man’s land where there are probably a lot more bugs to find. We’ll look at how Windows identifies USB devices, decides which driver to install, and then where it downloads the driver from. Armed with that knowledge, we’ll take a ~$5 Digispark Kickstarter Attiny85 board (https://smile.amazon.com/s?k=digispark+kickstarter+attiny85) and emulate a Razer device to trigger the vulnerability. If you bring your own board you can go home with a Windows master key (assuming no patches are released). Please come with the Arduino IDE installed for the full DIY experience.