New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
ID: 1325a231-4e91-5233-b84b-7356806f94dd
STIX ID: report--1325a231-4e91-5233-b84b-7356806f94dd
Feed Name: Bleeping Computer
A researcher published a public proof-of-concept called "MiniPlasma" that exploits a flaw in the Windows Cloud Filter driver (cldflt.sys / HsmOsBlockPlaceholderAccess) to achieve SYSTEM privileges on fully patched Windows 11. The exploit reproduces a previously reported CVE-2020-17103 issue that the researcher claims remains unpatched; testing by third parties confirmed SYSTEM escalation. The release is part of a series of recent Windows zero-day disclosures by the same researcher.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
