ANDROID Motorola Moto Pad 70 Specs: 12.1-inch 2.5K Display, 5G, and Moto Pen GAMES Baldur’s Gate 3 Mod Adds Over-The-Shoulder Third-Person Camera AMD Asus ZenBook 14 Air 2026 launches in China with OLED display ACCESSORIES Lenovo Legion Y7MG Mouse Launches with 8,000 Hz Polling and 59g Weight ANDROID Xiaomi 18 Pro Duo Returns Globally With Rear Screen ACCESSORIES Lenion R7 RT75 keyboard launches with Hall effect switches for $192 ACCESSORIES Nanoleaf Smart LED Monitor Stand Launches with 102 RGB Zones for $170 GAMES Amazon Luna bets on $1,000 consoles to boost cloud gaming appeal GAMES The First Berserker: Khazan Cracked After Year-Long Denuvo Standoff STEAM Crimson Desert Patch 1.15.00 Fixes Aerial Combat and HDR Glitches AMD Acemagic F9A Mini-PC Ships with AMD Ryzen AI Max+ and 128 GB RAM STEAM Free Zombie Shooter Codename CURE II Hits Steam With Deck Verified Support ACCESSORIES Samsung Unveils Official Cases for Galaxy Z Fold 8, Fold 8 Ultra, and Flip 8 INTEL Lenovo IdeaPad Slim 5 13IWC11 Launches with 120 Hz Display and 24.7-Hour Battery

MiniPlasma Zero-Day Grants SYSTEM Access On Fully Patched Windows 11

Lena Fischer 0 comments 2 min read

A new zero-day exploit named MiniPlasma grants SYSTEM access on fully patched Windows 11 machines, targeting a flaw in the Cloud Filter driver.

MiniPlasma Zero-Day Grants SYSTEM Access On Fully Patched Windows 11
SOFTWARE AND UPDATES

A researcher known as Chaotic Eclipse has published a working zero-day exploit named MiniPlasma that grants SYSTEM-level access on fully patched Windows 11 systems. The vulnerability affects Windows 11 Pro machines running the May 2026 Patch Tuesday update. Security researcher Will Dormann independently verified the exploit on a standard user account.

New exploit targets cldflt.sys driver in fully patched systems

The flaw resides in the Windows Cloud Filter driver, specifically in the cldflt.sys file. The bug exists within a routine called HsmOsBlockPlaceholderAccess. Chaotic Eclipse abused how the driver handles registry key creation through an undocumented API. This allows a standard user to create arbitrary registry keys in the .DEFAULT user hive without proper access checks. The exploit relies on a race condition, meaning success rates vary on real hardware.

The vulnerability is tracked as CVE-2020-17103 and was originally reported to Microsoft in September 2020 by Google Project Zero researcher James Forshaw. Microsoft supposedly patched the issue in December 2020. Chaotic Eclipse ran Forshaw's original proof-of-concept unmodified and confirmed it still works. The researcher stated uncertainty regarding whether Microsoft never patched the issue or if the patch was silently rolled back for unknown reasons.

MiniPlasma is part of a series of recent Windows privilege escalation disclosures by Chaotic Eclipse. Previous disclosures include BlueHammer, RedSun, and GreenPlasma. The researcher cites dissatisfaction with Microsoft's bug bounty handling and patch verification as the motivation for these public releases. Microsoft previously stated that it supports coordinated vulnerability disclosure as an industry practice but has not commented on MiniPlasma specifically.

Source: NotebookCheck

Discussion

0 comments

Leave a comment