It's interesting to see mention of 0-days against USB drivers as a vector, says "AFAIK, none of those have been publicly discussed." It seems very likely there are vulnerable drivers.
Block layer or filesystem driver vulnerabilities would be even better – no special hardware needed. Just buy a load of cheap flash drives, copy over your malicious partition table or filesystem, and you're set.