GAMES CD Projekt Red Confirms The Witcher 3: Wild Hunt Remastered 2026 Update GAMES Hytale developer offers $15,000 to first streamer who defeats Gobliterator boss GAMES Activision publicly calls out pro player for boosting after unbanning request GAMES Rockstar Games quietly removes GTA 6 map leak from $400 Collector’s Edition store page GAMES Demon’s Souls Lore Book Released in Russia with Premium Physical Features GAMES Hypixel Studios Offers Cash Prize For Defeating Hytale’s Gobliterator Boss PHONES iQOO 16 camera specs confirmed: 79% more light capture with 50MP OV50Q main sensor NINTENDO Reddit Moderator Ordered to Pay Nintendo $4.5 Million for Pirated Switch Game Networks ANDROID Google Gemini takes phone calls for you, but requires Pixel 11 and a paid subscription GAMES Bethesda rolls Obsidian Entertainment into parent company, retains Feargus Urquhart as studio head PLAYSTATION 5 Remedy’s Control Resonant Hits 34,000 Concurrent Players, Surpassing Original Control’s Peak CONSOLES Console Heroes releases SEGA Game Gear blind boxes with 2-inch figures for $4.49 TABLETS Huawei MatePad Air Z starts at around $446 with 12-inch 144Hz PaperMatte display HANDHELD GAMING iQOO Pad Ultra launches with 165Hz OLED display and 4,500-nit peak brightness

MiniPlasma Zero-Day Grants SYSTEM Access On Fully Patched Windows 11

Lena Fischer 2 min read

A new zero-day exploit named MiniPlasma grants SYSTEM access on fully patched Windows 11 machines, targeting a flaw in the Cloud Filter driver.

MiniPlasma Zero-Day Grants SYSTEM Access On Fully Patched Windows 11
SOFTWARE AND UPDATES

A researcher known as Chaotic Eclipse has published a working zero-day exploit named MiniPlasma that grants SYSTEM-level access on fully patched Windows 11 systems. The vulnerability affects Windows 11 Pro machines running the May 2026 Patch Tuesday update. Security researcher Will Dormann independently verified the exploit on a standard user account.

New exploit targets cldflt.sys driver in fully patched systems

The flaw resides in the Windows Cloud Filter driver, specifically in the cldflt.sys file. The bug exists within a routine called HsmOsBlockPlaceholderAccess. Chaotic Eclipse abused how the driver handles registry key creation through an undocumented API. This allows a standard user to create arbitrary registry keys in the .DEFAULT user hive without proper access checks. The exploit relies on a race condition, meaning success rates vary on real hardware.

The vulnerability is tracked as CVE-2020-17103 and was originally reported to Microsoft in September 2020 by Google Project Zero researcher James Forshaw. Microsoft supposedly patched the issue in December 2020. Chaotic Eclipse ran Forshaw's original proof-of-concept unmodified and confirmed it still works. The researcher stated uncertainty regarding whether Microsoft never patched the issue or if the patch was silently rolled back for unknown reasons.

MiniPlasma is part of a series of recent Windows privilege escalation disclosures by Chaotic Eclipse. Previous disclosures include BlueHammer, RedSun, and GreenPlasma. The researcher cites dissatisfaction with Microsoft's bug bounty handling and patch verification as the motivation for these public releases. Microsoft previously stated that it supports coordinated vulnerability disclosure as an industry practice but has not commented on MiniPlasma specifically.

Source: NotebookCheck