Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM

1 min read
Source: CyberSecurityNews
Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM
Photo: CyberSecurityNews
TL;DR Summary

A publicly released PoC for the Windows 'MiniPlasma' zero-day privilege-escalation flaw lets unprivileged users gain SYSTEM privileges by exploiting the Cloud Filter driver’s HsmOsBlockPlaceholderAccess race condition and writing to the .DEFAULT hive. The bug traces to CVE-2020-17103 (originally patched in 2020 by Microsoft) but the PoC shows the flaw remains exploitable; Nightmare-Eclipse released the exploit on GitHub on May 13, 2026, after May Patch Tuesday, increasing risk as weaponized code circulates and affects all Windows versions. Organizations should monitor Microsoft’s response and apply patches when available.

Share this article

Reading Insights

Total Reads

0

Unique Readers

14

Time Saved

57 min

vs 58 min read

Condensed

99%

11,46286 words

Want the full story? Read the original article

Read on CyberSecurityNews