HomeSecurityMiniPlasma: New Windows zero-day worries admins

MiniPlasma: New Windows zero-day worries admins

A new case is coming to shake up the Windows, as a security researcher has published a proof-of-concept exploit for a serious zero-day privilege escalation vulnerability dubbed “MiniPlasma.” The exploit reportedly allows an attacker to gain SYSTEM privileges — the highest level of access in Windows — even on fully updated Windows 11 systems.

MiniPlasma Windows zero-day

The discovery was made by cybersecurity researcher Chaotic Eclipse, also known asNightmare Eclipse, who published both the source code and the compiled executable on GitHub. According to him, the decision to make the exploit publicly available is related to his frustration with vulnerability management Microsoft's , and specifically with an older security issue that, he claims, was never substantially fixed.

The connection to CVE-2020-17103

The new zero-day appears to be directly related to the 'cldflt.sys' Cloud Filter driver, and specifically the 'HsmOsBlockPlaceholderAccess' routine. The issue was originally discovered in 2020 by James Forshaw of Google Project Zero and was then given the identifier CVE-2020-17103.

See also: NGINX: Critical vulnerability used in attacks

Microsoft had announced that the vulnerability was fixed in December 2020, via a Patch Tuesday update. However, according to Chaotic Eclipse, the exact same exploit still works without any special modifications even today.

The researcher claims that Microsoft either never fixed the problem or silently removed the patch in a later version of Windows. More worryingly, Google's original proof-of-concept reportedly runs without significant code changes.

How MiniPlasma works

The vulnerability appears to exploit the way the Windows Cloud Filter Driver handles the creation of registry keys through an undocumented API called “CfAbortHydration”.

According to technical analysis, the exploit allows the creation of arbitrary registry keys in the .DEFAULT user group without the necessary access controls. Through this process, a user with limited privileges can proceed to privilege escalation and eventually obtain a SYSTEM shell.

MiniPlasma: New Windows zero-day worries admins

SYSTEM access is considered extremely dangerous, as it gives complete control over the operating system. An attacker could theoretically install malware, disable security mechanisms, steal data , or gain permanent access to the device.

Tests confirm the problem

According to information from BleepingComputer, the exploit was successfully tested on a fully updated Windows 11 Pro system with the latest Patch Tuesday updates of May 2026.

See also: Pwn2Own Berlin 2026: Researchers won $1,298,250 for 47 zero-days

During testing, a simple user account without elevated privileges was used. After running MiniPlasma, the exploit opened a command prompt with SYSTEM privileges, confirming that privilege escalation is possible.

Will Dormann , principal vulnerability analyst at Tharros , also confirmed the vulnerability, saying that it works in the latest public versions of Windows 11. However, he noted that the exploit does not appear to work in the latest Canary Insider Preview builds , which may indicate that Microsoft has already started internal fixes.

The new series of zero-days that worries Microsoft

MiniPlasma is not an isolated case. Chaotic Eclipse has published a whole series of zero-day exploits for Windows, causing intense concern in the cybersecurity community.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It started with BlueHammer, a local privilege escalation flaw documented as CVE-2026-33825. It was followed by RedSun and the DoS tool “UnDefend”, which targeted Windows Defender.

According to the researcher, several of these vulnerabilities were later exploited in real attacks. At the same time, he accuses Microsoft of in some cases fixing problems "silently", without officially assigning CVE identifiers.

YellowKey and GreenPlasma were also introduced in the same month . YellowKey is considered particularly serious, as it involves bypassing BitLocker in Windows 11 and Windows Server 2022/2025 , allowing access to unlocked drives protected exclusively via TPM.

See also: VMware Fusion: Vulnerability allows privilege escalation

MiniPlasma: New Windows zero-day worries admins

The conflict with Microsoft and the reactions

Chaotic Eclipse claims that the public disclosures are a form of protest against Microsoft's vulnerability disclosure and bug bounty process . In particularly pointed statements, he accused the company of hostile behavior towards independent security researchers.

For its part, Microsoft has reiterated that it supports coordinated vulnerability disclosure and that it continues to investigate security issues with the aim of protecting users through updates.

The incident, however, highlights once again how critical Windows security remains in the era of zero-days and how difficult it is even for large companies to fully eliminate complex, low-level vulnerabilities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS