A researcher known as Chaotic Eclipse has published a working zero-day exploit named MiniPlasma that grants SYSTEM-level access on fully patched Windows 11 systems. The vulnerability affects Windows 11 Pro machines running the May 2026 Patch Tuesday update. Security researcher Will Dormann independently verified the exploit on a standard user account.
New exploit targets cldflt.sys driver in fully patched systems
The flaw resides in the Windows Cloud Filter driver, specifically in the cldflt.sys file. The bug exists within a routine called HsmOsBlockPlaceholderAccess. Chaotic Eclipse abused how the driver handles registry key creation through an undocumented API. This allows a standard user to create arbitrary registry keys in the .DEFAULT user hive without proper access checks. The exploit relies on a race condition, meaning success rates vary on real hardware.
The vulnerability is tracked as CVE-2020-17103 and was originally reported to Microsoft in September 2020 by Google Project Zero researcher James Forshaw. Microsoft supposedly patched the issue in December 2020. Chaotic Eclipse ran Forshaw's original proof-of-concept unmodified and confirmed it still works. The researcher stated uncertainty regarding whether Microsoft never patched the issue or if the patch was silently rolled back for unknown reasons.
MiniPlasma is part of a series of recent Windows privilege escalation disclosures by Chaotic Eclipse. Previous disclosures include BlueHammer, RedSun, and GreenPlasma. The researcher cites dissatisfaction with Microsoft's bug bounty handling and patch verification as the motivation for these public releases. Microsoft previously stated that it supports coordinated vulnerability disclosure as an industry practice but has not commented on MiniPlasma specifically.
Source: NotebookCheck




Discussion
0 comments