
"Codenamed MiniPlasma, the vulnerability impacts "cldflt.sys," which refers to the Windows Cloud Files Mini Filter Driver, and resides in a routine named "HsmOsBlockPlaceholderAccess," adding it was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020."
"Although it was assumed that the shortcoming was fixed by Microsoft in December 2020 as part of CVE-2020-17103, Chaotic Eclipse said further investigation has uncovered that the "exact same issue [...] is actually still present, unpatched.""
""I'm unsure if Microsoft just never patched the issue or the patch was silently rolled back at some point for unknown reasons. The original PoC by Google worked without any changes," the researcher added. "To highlight this issue, I weaponized the original PoC to spawn a SYSTEM shell. It seems to work reliably in my machines butsuccess rate may vary since it's a race condition.""
"In a post shared on Mastodon, security researcher Will Dormann said MiniPlasma works "reliably" to open a "cmd.exe" prompt with SYSTEM privileges on Windows 11 systems running the latest May 2026 updates. "I'll note that it does not seem to work on the latest Insider Preview Canary Windows 11," Dormann pointed out."
MiniPlasma is a Windows privilege escalation proof-of-concept that grants attackers SYSTEM privileges on fully patched systems. The flaw affects cldflt.sys, the Windows Cloud Files Mini Filter Driver, and occurs in the routine HsmOsBlockPlaceholderAccess. The issue was originally reported to Microsoft in September 2020 and was previously believed fixed in December 2020 under CVE-2020-17103. Further investigation indicates the exact same issue remains unpatched, with the original proof-of-concept working without changes. The exploit is described as a race condition, so reliability may vary. All Windows versions are likely affected, though it may not work on the latest Insider Preview Canary builds. Microsoft later fixed another related privilege escalation issue in the same component, CVE-2025-62221, which was reportedly exploited by unknown threat actors.
#windows-privilege-escalation #cldfltsys #cloud-files-mini-filter-driver #system-shell #race-condition-vulnerability
Read at The Hacker News
Unable to calculate read time
Collection
[
|
...
]