Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

How space and AI can outshine wildfires

MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

Apple’s Siri revamp could include automatic chat deletion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems
Identity

MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

By May 18, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 18, 2026Zero-day/vulnerabilities

Chaotic Eclipse, the security researchers behind the recently revealed Windows flaws YellowKey and GreenPlasma, has released a proof of concept (PoC) for a Windows privilege escalation zero-day flaw that grants an attacker SYSTEM privileges on a fully patched Windows system.

Codenamed MiniPlasma, the vulnerability affects ‘cldflt.sys’, which refers to the Windows Cloud Files Mini Filter Driver, and resides in a routine named ‘HsmOsBlockPlaceholderAccess’, it said, adding that the vulnerability was first reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020.

The flaw was thought to have been fixed by Microsoft as part of CVE-2020-17103 in December 2020, but Chaotic Eclipse said further investigation “found that the exact same issue existed.” […] It’s actually still there and hasn’t been patched. ”

“We do not know whether Microsoft simply did not patch this issue or whether the patch was silently rolled back at some point for unknown reasons. The original PoC by Google worked without any changes,” the researchers added. “To highlight this issue, I weaponized the original PoC to generate a SYSTEM shell. It seems to work reliably on my machine, but success rates may vary due to race conditions.”

The researchers further noted that all Windows versions can be affected by this vulnerability.

In a post shared on Mastodon, security researcher Will Dorman said MiniPlasma “reliably” works for opening “cmd.exe” prompts with SYSTEM privileges on Windows 11 systems running the latest May 2026 update. “The latest Insider Preview Canary does not appear to work on Windows 11,” Dormann noted.

In December 2025, Microsoft also addressed another privilege escalation flaw in the same component (CVE-2025-62221, CVSS score: 7.8), which we identified as being exploited by an unknown attacker.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleApple’s Siri revamp could include automatic chat deletion
Next Article How space and AI can outshine wildfires

Related Posts

NGINX CVE-2026-42945 can be exploited in the wild to cause worker crash and possible RCE

May 17, 2026

Grafana GitHub token compromise led to codebase downloads and extortion attempts

May 17, 2026

Actively exploited funnel builder flaw allows WooCommerce checkout skimming

May 16, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How space and AI can outshine wildfires

MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

Apple’s Siri revamp could include automatic chat deletion

Why trust is a big issue in the Elon Musk and OpenAI trial

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.