Skip to content
MiniPlasma Zero-Day Hits Fully Patched Windows PCs

MiniPlasma Zero-Day Hits Fully Patched Windows PCs

Pcquest May 18, 2026

An updated Windows machine should seem safer than one that doesn't have all of its patches installed. This is not so with MiniPlasma; this is a good reminder that not all patches eliminate all threats. An open proof of concept exists for a Windows zero day that shows how an attacker can obtain SYSTEM-level access to fully patched targets through the exploitation of a stack overflow within the cldflt.sys (Cloud Files Minifilter Driver) located at HsmOsBlockPlaceholderAccess .

The original discoverer is Chaotic Eclipse, who is also associated with the recent YellowKey and GreenPlasma vulnerabilities. The importance of MiniPlasma lies in the fact that SYSTEM access is nearly equivalent to possession of the encryption keys to the kingdom on a Windows device.

MiniPlasma is a local privilege escalation vulnerability, the kind where the bad guy already needs a foothold on the system to get started. That could be a dodgy account, some malware to get you in the door, or any other entry point an attacker might use.

Once they've got their foot in, MiniPlasma can help them bump that up to SYSTEM privilege, and from there, the possibilities are endless. They can run pretty much any command they want on that machine, with total control.

It's not the same as some remote exploit that just magically breaks in all by itself, though in real-world attacks, privilege escalation is often the step after the first.

Chaotic Eclipse reckons that the MiniPlasma issue somehow seems tied to a bug that Google Project Zero's James Forshaw flagged up to Microsoft way back in September 2020. Now Microsoft issued a fix for that one in December 2020 as CVE-2020-17103 , but it seems James Forshaw is saying that same issue is still kicking around.

And to make things even more uncomfortable, the proof of concept he wrote way back when still works; no changes needed. He just had to modify it to give up a SYSTEM shell instead.

Which raises a pretty big question: Was the original fix for CVE-2020-17103 not done right, or maybe some other change to Windows somehow reintroduced the bug?

Security researcher Will Dormann said MiniPlasma worked reliably on Windows 11 systems running the latest May 2026 updates. He also noted that it did not seem to work on the latest Windows 11 Insider Preview Canary build.

That detail is important, but it does not equal a public fix for mainstream users. At the time of the report, Microsoft had not issued a fresh advisory or assigned a new CVE for MiniPlasma.

Until Microsoft provides official guidance, users should avoid running unknown files and keep Windows updates enabled. IT teams should monitor for unusual system-level command prompts, suspicious privilege jumps, and unexpected activity tied to cloud file handling.

MiniPlasma is not a reason to panic. It is a reason to watch closely. Fully patched does not always mean fully protected, especially when a public proof of concept is already out in the open.

Windows BitLocker zero day raises fresh risks for encrypted drives

Chrome Zero-Day Attack Breaks Cover: Update Now to Stay Safe

Valorant finally takes aim at smurfs Riot rolls out MFA lock for real accountability

Valorant finally takes aim at smurfs Riot rolls out MFA lock for real accountability