logo

MiniPlasma: Windows privilege escalation zero-day affects fully patched systems

ID: 1d83a6e0-d811-58e0-bd26-025f373eda74

STIX ID: report--1d83a6e0-d811-58e0-bd26-025f373eda74

Feed Name: ThreatLocker Blog

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

MiniPlasma is a publicly released, weaponized local privilege escalation exploit targeting CVE-2020-17103 in the Windows Cloud Filter driver (cldflt.sys). Researchers (ThreatLocker) confirmed it can elevate a standard user to SYSTEM on fully patched Windows 11 and some Windows Server builds; no official patch is available. Mitigations recommended include default-deny application allowlisting to block payload execution and monitoring specific registry paths for indicators of exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.