Briefing

MiniPlasma Windows Zero‑Day PoC Gives Attackers SYSTEM Access on Patched Systems

security
by Lawrence Abrams · CVE-2020-17103 CVE-2026-33825

Patch Windows to the latest cumulative update and verify cldflt.sys is updated to close the MiniPlasma flaw.

What to do now

Patch Windows to the latest cumulative update and verify cldflt.sys is updated to close the MiniPlasma flaw.

Summary

A new Windows privilege‑escalation zero‑day, codenamed MiniPlasma, has been exposed by security researcher Chaotic Eclipse. The flaw targets the cldflt.sys driver, part of the Windows Cloud Files Mini Filter Driver, and allows an attacker to gain SYSTEM privileges without any user interaction. The proof‑of‑concept (PoC) demonstrates that the vulnerability can be triggered by loading a specially crafted file, even on fully patched Windows installations. No official CVE identifier has been assigned yet, and Microsoft has not released a patch, leaving the flaw actively exploitable.

Chaotic Eclipse, known for earlier disclosures such as YellowKey and GreenPlasma, released the PoC on its public channel. The PoC shows how a malicious file can be dropped onto a system, causing the cldflt.sys driver to process it and elevate the attacker’s privileges to SYSTEM level. Because the driver is loaded by default on all Windows machines, the attack can affect a wide range of devices, from personal computers to enterprise servers. The researchers emphasize that the exploit requires no user action beyond the presence of the malicious file, making it a high‑risk threat for any environment that accepts external files.

In response, Microsoft has not yet issued a patch or a CVE, but security teams are advised to apply the latest cumulative updates as soon as they become available. Organizations are urged to monitor for signs of exploitation, such as unexpected SYSTEM‑level activity, and to prepare for a swift deployment of the fix once it is released. The MiniPlasma flaw is part of a broader trend of Windows kernel exploits that continue to surface, underscoring the need for vigilant patch management and threat monitoring.

The potential for full system compromise means that any successful exploitation could allow attackers to install backdoors, steal data, or pivot to other systems within a network. As the vulnerability remains unpatched, the cybersecurity community is closely watching for any signs of real‑world attacks and for Microsoft’s response.

Key changes

  • MiniPlasma exploits cldflt.sys HsmOsBlockPlaceholderAccess routine.
  • Original CVE‑2020‑17103 was fixed in Dec 2020.
  • Exploit works on fully patched Windows 11 Pro.
  • BleepingComputer confirmed SYSTEM privilege escalation.
  • MiniPlasma abuses CfAbortHydration API.
  • Microsoft claims the bug was fixed.
  • Researcher alleges silent rollback or no patch.
  • The flaw remains present in current builds.

Affects

enterprise

Source angles · 3 perspectives

Bleeping Computer
Independent angle

New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

Open
The Hacker News
Independent angle

MiniPlasma Windows Privilege Escalation Zero-Day Affects Fully Patched Systems

Open
The Hacker News
Independent angle

Chaotic Eclipse Releases PoC for MiniPlasma Windows Privilege Escalation Zero‑Day

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting