A new case is coming to shake up the Windows, as a security researcher has published a proof-of-concept exploit for a serious zero-day privilege escalation vulnerability dubbed “MiniPlasma.” The exploit reportedly allows an attacker to gain SYSTEM privileges — the highest level of access in Windows — even on fully updated Windows 11 systems.

The discovery was made by cybersecurity researcher Chaotic Eclipse, also known asNightmare Eclipse, who published both the source code and the compiled executable on GitHub. According to him, the decision to make the exploit publicly available is related to his frustration with vulnerability management Microsoft's , and specifically with an older security issue that, he claims, was never substantially fixed.
The connection to CVE-2020-17103
The new zero-day appears to be directly related to the 'cldflt.sys' Cloud Filter driver, and specifically the 'HsmOsBlockPlaceholderAccess' routine. The issue was originally discovered in 2020 by James Forshaw of Google Project Zero and was then given the identifier CVE-2020-17103.
See also: NGINX: Critical vulnerability used in attacks
Microsoft had announced that the vulnerability was fixed in December 2020, via a Patch Tuesday update. However, according to Chaotic Eclipse, the exact same exploit still works without any special modifications even today.
The researcher claims that Microsoft either never fixed the problem or silently removed the patch in a later version of Windows. More worryingly, Google's original proof-of-concept reportedly runs without significant code changes.
How MiniPlasma works
The vulnerability appears to exploit the way the Windows Cloud Filter Driver handles the creation of registry keys through an undocumented API called “CfAbortHydration”.
According to technical analysis, the exploit allows the creation of arbitrary registry keys in the .DEFAULT user group without the necessary access controls. Through this process, a user with limited privileges can proceed to privilege escalation and eventually obtain a SYSTEM shell.

SYSTEM access is considered extremely dangerous, as it gives complete control over the operating system. An attacker could theoretically install malware, disable security mechanisms, steal data , or gain permanent access to the device.
Tests confirm the problem
According to information from BleepingComputer, the exploit was successfully tested on a fully updated Windows 11 Pro system with the latest Patch Tuesday updates of May 2026.
See also: Pwn2Own Berlin 2026: Researchers won $1,298,250 for 47 zero-days
During testing, a simple user account without elevated privileges was used. After running MiniPlasma, the exploit opened a command prompt with SYSTEM privileges, confirming that privilege escalation is possible.
Will Dormann , principal vulnerability analyst at Tharros , also confirmed the vulnerability, saying that it works in the latest public versions of Windows 11. However, he noted that the exploit does not appear to work in the latest Canary Insider Preview builds , which may indicate that Microsoft has already started internal fixes.
The new series of zero-days that worries Microsoft
MiniPlasma is not an isolated case. Chaotic Eclipse has published a whole series of zero-day exploits for Windows, causing intense concern in the cybersecurity community.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It started with BlueHammer, a local privilege escalation flaw documented as CVE-2026-33825. It was followed by RedSun and the DoS tool “UnDefend”, which targeted Windows Defender.
According to the researcher, several of these vulnerabilities were later exploited in real attacks. At the same time, he accuses Microsoft of in some cases fixing problems "silently", without officially assigning CVE identifiers.
YellowKey and GreenPlasma were also introduced in the same month . YellowKey is considered particularly serious, as it involves bypassing BitLocker in Windows 11 and Windows Server 2022/2025 , allowing access to unlocked drives protected exclusively via TPM.
See also: VMware Fusion: Vulnerability allows privilege escalation

The conflict with Microsoft and the reactions
Chaotic Eclipse claims that the public disclosures are a form of protest against Microsoft's vulnerability disclosure and bug bounty process . In particularly pointed statements, he accused the company of hostile behavior towards independent security researchers.
For its part, Microsoft has reiterated that it supports coordinated vulnerability disclosure and that it continues to investigate security issues with the aim of protecting users through updates.
The incident, however, highlights once again how critical Windows security remains in the era of zero-days and how difficult it is even for large companies to fully eliminate complex, low-level vulnerabilities.
Source: www.bleepingcomputer.com
