Windows 'MiniPlasma' Exploit: SYSTEM Access, Proof-of-Concept Public
Unpatched flaw in Windows Cloud Filter driver hands SYSTEM access to attackers. Microsoft's radio silence continues.

A new Windows flaw, dubbed 'MiniPlasma,' is out there. It lets attackers snag SYSTEM-level access even on fully patched machines. Cybersecurity researcher Chaotic Eclipse just dropped the exploit publicly. It zeros in on a bug in the Windows Cloud Filter driver, specifically the 'HsmOsBlockPlaceholderAccess' routine. Here's the kicker: James Forshaw of Google Project Zero first reported this vulnerability back in 2020. It was supposedly patched. But it's back.
A Scar Reopened
This MiniPlasma exploit? It points to a worrying lapse in Microsoft's patch management. Chaotic Eclipse says the 2020 issue, CVE-2020-17103, still works. Microsoft claimed a fix in December 2020. Yet BleepingComputer and other security pros confirm the exploit runs just fine on the latest Windows 11 updates.
Hardware keys and password managers used by security pros.
It lets attackers create arbitrary registry keys, totally bypassing access checks. Think about that. This can bump a regular user's privileges straight up to SYSTEM level. Pretty big security risk, wouldn't you say?
Not Their First Rodeo
This isn't Chaotic Eclipse's first rodeo. The researcher has dropped a series of zero-day vulnerabilities. It's a protest, actually, against how Microsoft handles bug bounties and vulnerability disclosures. Some of these, like BlueHammer, RedSun, and UnDefend, have even been actively exploited after they went public.
- BlueHammer: A local privilege escalation flaw.
- RedSun: Another escalation bug. Microsoft, for its part, patched this one quietly.
- UnDefend: A tool to hit Windows Defender with a Denial of Service attack.
Europe's Stake
Europe's cybersecurity scene? It's feeling this keenly. Windows platforms are everywhere, across pretty much every industry. And GDPR? That adds another layer of pain. Data breaches from these kinds of flaws could mean hefty fines. Remember when software giants faced huge scrutiny and penalties over security oversights? Yeah, like that.
So, What Now?
For you, the user, or you, the IT admin? This exploit means you need to be on your toes. Vigilance. Proactive security. Update your systems. Get extra security tools. Seriously. It's about mitigating those potential risks. And keep an eye on Microsoft. See what they do about patches.
The Big Questions
- Microsoft hasn't said a word about MiniPlasma. Not officially, anyway.
- No one knows if a new patch is coming. Or when.
- How much is this actually being exploited out there? Pure speculation right now.
Why It Matters
The MiniPlasma exploit? It really chips away at trust in Microsoft's patching. A vulnerability that was supposedly fixed, now back again. Doesn't exactly inspire confidence in their security processes, does it? Threats keep evolving. Microsoft needs solid, transparent patch management. It's about user trust. It's about data integrity. Simple as that.
Hardware keys and password managers used by security pros.
Shop security gear →One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.
More from Security

Malware Disguised as OpenAI Found on Hugging Face
A fake OpenAI repo on Hugging Face pushed malware disguised as AI tools, targeting Windows users with info-stealing tactics.

AI Just Changed Mac Cybersecurity Training, Big Time
Forget annual security videos. Dashlane and KnowBe4 are using AI to give Mac admins real-time, context-aware training. When you mess up, you learn. Immediately.

WordPress Funnel Builder Bug Exposes 40K Sites to Card Theft
A vulnerability in Funnel Builder for WordPress allows attackers to steal credit card data from over 40,000 WooCommerce sites. Update now!

Outlook Zero-Click Flaw Lets Hackers Bypass Firewalls
A critical Outlook vulnerability lets attackers compromise systems via email. No user interaction needed, making it a serious threat.
Don’t miss these

Brainiac Actor Pitches Villain as 'Incarnation of Satan' in New Superman Film
Lars Eidinger teases his portrayal of Brainiac in Man of Tomorrow, likening the villain to 'an incarnation of Satan.' The film debuts July 2027.

Microsoft Scraps Teams' Together Mode for Simplicity
Microsoft's Together Mode, that virtual meeting feature, is getting retired. The company wants a simpler interface, better video, and less platform chaos.

Siri Overhaul: Auto-Delete Chats Could Be Apple's Privacy Play
Apple's next Siri update, expected in June, could introduce auto-delete chat features, prioritizing user privacy in a direct challenge to competitors.
Unlock Hidden Pixel Features for Enhanced Daily Use
Uncover hidden gems on the Pixel 10 Pro like Quick Tap and the Magnifier app to enhance your phone experience.

GrandPerspective 3.7 Updates Mac Disk Tool with Liquid-Glass
GrandPerspective 3.7 just dropped, bringing Liquid-Glass design and tighter integration with macOS 26 Tahoe. About time.

Super Mario RPG Drops to $15 in GameStop's Flash Sale
Nintendo fans can snag Super Mario RPG for just $15 at GameStop, plus savings on other Switch titles like Sonic Racing and Hyrule Warriors.