This is a well-known mode of attack and some anti-virus software have protections against it:
https://www.kaspersky.com/blog/weaponized-usb-devices/26495/
> USB Keyboard Guard
> Protects you against manipulated USB devices that pretend to be keyboards, even though they look like USB sticks or external hard drives.
it has no way of telling that that device isn't a logitech keyboard, and can't tell that it's not the user opening up elevated cmd.exe and accepting the prompt
> Kaspersky Endpoint Security's technology will not authorize any HIDs unless the user inputs a code using a HID already authorized to do so.