• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
miniplasma windows 0 day enables system privilege escalation on fully patched

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

You are here: Home / General Cyber Security News / MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
May 18, 2026

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.

Codenamed MiniPlasma, the vulnerability impacts “cldflt.sys,” which refers to the Windows Cloud Files Mini Filter Driver, and resides in a routine named “HsmOsBlockPlaceholderAccess,” adding it was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020.

Although it was assumed that the shortcoming was fixed by Microsoft in December 2020 as part of CVE-2020-17103, Chaotic Eclipse said further investigation has uncovered that the “exact same issue […] is actually still present, unpatched.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“I’m unsure if Microsoft just never patched the issue or the patch was silently rolled back at some point for unknown reasons. The original PoC by Google worked without any changes,” the researcher added. “To highlight this issue, I weaponized the original PoC to spawn a SYSTEM shell. It seems to work reliably in my machines butsuccess rate may vary since it’s a race condition.”

The researcher further pointed out that all Windows versions are likely affected by this vulnerability.

In a post shared on Mastodon, security researcher Will Dormann said MiniPlasma works “reliably” to open a “cmd.exe” prompt with SYSTEM privileges on Windows 11 systems running the latest May 2026 updates. “I’ll note that it does not seem to work on the latest Insider Preview Canary Windows 11,” Dormann pointed out.

In December 2025, Microsoft also addressed another privilege escalation flaw in the same component (CVE-2025-62221, CVSS score: 7.8), which it identified as exploited by unknown threat actors.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «nginx cve 2026 42945 exploited in the wild, causing worker crashes and NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
  • NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
  • Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
  • Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
  • Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
  • Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
  • What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
  • TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
  • On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
  • CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

Copyright © TheCyberSecurity.News, All Rights Reserved.