Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/Critical MiniPlasma Zero-Day Vulnerability in Windows Lets Attackers Gain SYSTEM Access
CyberSecurity News

Critical MiniPlasma Zero-Day Vulnerability in Windows Lets Attackers Gain SYSTEM Access

Key Takeaways A critical zero-day vulnerability, dubbed “MiniPlasma,” has emerged in Windows, allowing attackers to escalate privileges to SYSTEM level. The flaw, impacting the cldflt.sys...

Jennifer sherman
Jennifer sherman
May 18, 2026 3 Min Read
72 0

Key Takeaways

  • A critical zero-day vulnerability, dubbed “MiniPlasma,” has emerged in Windows, allowing attackers to escalate privileges to SYSTEM level.
  • The flaw, impacting the cldflt.sys Cloud Filter driver, was previously reported and supposedly patched by Microsoft in 2020 (CVE-2020-17103), but a security researcher found it remains exploitable.
  • A public proof-of-concept (PoC) exploit is available on GitHub, demonstrating reliable SYSTEM access on fully patched Windows systems.
  • All Windows versions are affected, and no official patch is currently available, leaving systems vulnerable to immediate exploitation.

Critical Windows Zero-Day “MiniPlasma” Unleashes SYSTEM-Level Access

A severe zero-day vulnerability in Microsoft Windows, publicly identified as “MiniPlasma,” has been revealed, providing attackers with a straightforward path to achieve SYSTEM-level privileges on fully updated Windows installations. A working proof-of-concept (PoC) exploit for this privilege escalation flaw is now openly accessible, raising urgent concerns across the cybersecurity landscape.

Table Of Content

  • Key Takeaways
  • Critical Windows Zero-Day “MiniPlasma” Unleashes SYSTEM-Level Access
  • Re-Emergence of a Previously Patched Flaw
  • Technical Details of the MiniPlasma Exploit
  • What You Should Do

The exploit’s release by security researcher Nightmare-Eclipse on GitHub on May 13, 2026, coincided with claims that Microsoft had either failed to adequately address or had silently reverted a fix for an issue first reported six years prior. This timing, intentionally following Microsoft’s May 2026 Patch Tuesday, means organizations are left exposed without an immediate official remedy.

Re-Emergence of a Previously Patched Flaw

The vulnerability targets the HsmOsBlockPlaceholderAccess routine within the cldflt.sys Cloud Filter driver. This specific flaw was originally discovered and reported to Microsoft in September 2020 by Google Project Zero researcher James Forshaw. Microsoft subsequently assigned CVE-2020-17103 to the issue and reportedly released a fix as part of its December 2020 Patch Tuesday updates.

However, Nightmare-Eclipse’s independent research uncovered that the vulnerability described in Forshaw’s initial report remains exploitable, requiring no modifications to the original PoC code. The public release of the MiniPlasma exploit has rapidly garnered significant attention, with its GitHub repository quickly accumulating over 390 stars.

Technical Details of the MiniPlasma Exploit

The core of the “MiniPlasma” vulnerability resides in an improper access control mechanism that permits unprivileged users to create arbitrary registry keys within the .DEFAULT user hive. According to Google Project Zero’s findings, the HsmOsBlockPlaceholderAccess function fails to incorporate the OBJ_FORCE_ACCESS_CHECK flag when creating registry keys. This omission allows attackers to circumvent standard access restrictions, enabling writes to the .DEFAULT user hive—a privilege typically denied to standard users.

The exploit leverages this behavior by exploiting a race condition. It manipulates the RtlOpenCurrentUser function within the kernel, toggling between user and anonymous tokens. When this race condition is successfully won, the system opens the .DEFAULT hive for writing while the thread impersonation is temporarily reverted, thereby facilitating unauthorized key creation. Nightmare-Eclipse’s proof-of-concept on GitHub reliably demonstrates this, culminating in the spawning of a SYSTEM shell on multi-core systems after the race condition is met.

The vulnerability’s broad impact extends to all Windows versions, posing a substantial threat to enterprise environments, individual workstations, and systems utilizing cloud synchronization services. Tests confirm that executing the exploit from a standard user account successfully yields a command prompt with SYSTEM privileges, granting complete control over the compromised machine. Given that the Cloud Filter driver is fundamental to Windows cloud storage synchronization services like OneDrive, the vulnerable code is present across a vast array of Windows installations.

What You Should Do

  • Monitor for Official Patches: Immediately prepare to deploy any security updates released by Microsoft to address CVE-2020-17103 or a new CVE for this re-emerged vulnerability.
  • Implement Principle of Least Privilege: Ensure all users operate with the absolute minimum necessary privileges to perform their tasks. This limits the impact of successful privilege escalation exploits.
  • Enhance Endpoint Detection and Response (EDR): Utilize EDR solutions to monitor for unusual process activity, especially any attempts by non-SYSTEM accounts to modify critical system components or spawn shells with elevated privileges.
  • Review System Hardening: Regularly review and apply system hardening best practices to reduce the overall attack surface and mitigate the impact of potential exploits.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical WordPress Plugin Flaw Exposes Sites to Auth Bypass Attacks

Next Post

Windows 11 Update Fails With Error 0x800f0922, Microsoft Confirms

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us