MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
ID: 3e2ef9c0-f9bc-50dd-96fb-bb44a0a6157f
STIX ID: report--3e2ef9c0-f9bc-50dd-96fb-bb44a0a6157f
Feed Name: The Hacker News
Chaotic Eclipse published a proof-of-concept for a Windows privilege escalation zero-day dubbed "MiniPlasma" that targets the cldflt.sys Cloud Files Mini Filter Driver (routine HsmOsBlockPlaceholderAccess) and can spawn a SYSTEM shell on fully patched Windows systems. The researcher says the issue was originally reported by Google Project Zero in 2020 and appears unpatched despite an earlier related CVE; independent testing (including on Windows 11) shows the PoC can reliably escalate privileges, though it is a race condition and success may vary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
