Windows 'MiniPlasma' Exploit: SYSTEM Access, Proof-of-Concept Public
Unpatched flaw in Windows Cloud Filter driver hands SYSTEM access to attackers. Microsoft's radio silence continues.

A new Windows flaw, dubbed 'MiniPlasma,' is out there. It lets attackers snag SYSTEM-level access even on fully patched machines. Cybersecurity researcher Chaotic Eclipse just dropped the exploit publicly. It zeros in on a bug in the Windows Cloud Filter driver, specifically the 'HsmOsBlockPlaceholderAccess' routine. Here's the kicker: James Forshaw of Google Project Zero first reported this vulnerability back in 2020. It was supposedly patched. But it's back.
A Scar Reopened
This MiniPlasma exploit? It points to a worrying lapse in Microsoft's patch management. Chaotic Eclipse says the 2020 issue, CVE-2020-17103, still works. Microsoft claimed a fix in December 2020. Yet BleepingComputer and other security pros confirm the exploit runs just fine on the latest Windows 11 updates.
It lets attackers create arbitrary registry keys, totally bypassing access checks. Think about that. This can bump a regular user's privileges straight up to SYSTEM level. Pretty big security risk, wouldn't you say?
Not Their First Rodeo
This isn't Chaotic Eclipse's first rodeo. The researcher has dropped a series of zero-day vulnerabilities. It's a protest, actually, against how Microsoft handles bug bounties and vulnerability disclosures. Some of these, like BlueHammer, RedSun, and UnDefend, have even been actively exploited after they went public.
- BlueHammer: A local privilege escalation flaw.
- RedSun: Another escalation bug. Microsoft, for its part, patched this one quietly.
- UnDefend: A tool to hit Windows Defender with a Denial of Service attack.
Europe's Stake
Europe's cybersecurity scene? It's feeling this keenly. Windows platforms are everywhere, across pretty much every industry. And GDPR? That adds another layer of pain. Data breaches from these kinds of flaws could mean hefty fines. Remember when software giants faced huge scrutiny and penalties over security oversights? Yeah, like that.
So, What Now?
For you, the user, or you, the IT admin? This exploit means you need to be on your toes. Vigilance. Proactive security. Update your systems. Get extra security tools. Seriously. It's about mitigating those potential risks. And keep an eye on Microsoft. See what they do about patches.
The Big Questions
- Microsoft hasn't said a word about MiniPlasma. Not officially, anyway.
- No one knows if a new patch is coming. Or when.
- How much is this actually being exploited out there? Pure speculation right now.
Why It Matters
The MiniPlasma exploit? It really chips away at trust in Microsoft's patching. A vulnerability that was supposedly fixed, now back again. Doesn't exactly inspire confidence in their security processes, does it? Threats keep evolving. Microsoft needs solid, transparent patch management. It's about user trust. It's about data integrity. Simple as that.
Hardware keys and password managers used by security pros.
Shop security gear →Discuss this story
Got a take, a correction, or a follow-up tip? Reply where you read — we read everything.
Found an error? File a correction at /corrections. Substantive corrections are logged publicly.
One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.
More from Security

eBay's $55.7M Cyberstalking Settlement: A Corporate Culture of Coercion Exposed
Byte-Pulse investigates the eBay cyberstalking case, revealing a disturbing harassment campaign, executive involvement, and the broader implications for corporate ethics.

Google's Selfie Login: Convenience Meets Data Privacy Alarms
Google introduces a video selfie login, but the implications for data privacy and AI training warrant scrutiny beyond convenience

Apple's Rare Third macOS RC: Unpacking Security Concerns
Byte-Pulse explores the implications of Apple's unusual third Release Candidate for macOS updates, examining the severity of unannounced security fixes and their impact on European users

Google’s Legal Battle Against AI-Driven Cybercrime: Examining Outsider Enterprise
Google's lawsuit against Outsider Enterprise exposes differences in victim counts and sheds light on AI's role in cybercrime.
The Byte-Pulse Newsroom is the editorial system that produces Byte-Pulse's daily tech news coverage. Each story is cross-referenced across 3+ independent outlets, drafted with AI assistance by the newsroom system (Drafter → Editor → Fact-Checker → Polisher), and reviewed by Serhat Er, Editor-in-Chief, before publication. We disclose AI augmentation openly. Editorial accountability stays with the named editor on every article. Tips: editorial@byte-pulse.net.
Don’t miss these
Asus ROG Phone 9 vs Sony Xperia 1 VII: Which Niche Flagship Earns Your Money?
Deciding between the gaming-focused ROG Phone 9 and the creator-centric Xperia 1 VII? This guide breaks down every spec to help you choose.
Proton VPN vs NordVPN: Which One Earns Your Subscription?
A deep dive into Proton VPN and NordVPN, comparing their privacy, performance, features, and value, helping you make an informed decision.
Perplexity Pro vs ChatGPT Plus: Which AI Assistant Fits Your Workflow?
This guide lays out the strengths and approaches of Perplexity Pro and ChatGPT Plus, helping you identify which AI assistant aligns with your specific needs.

Pokémon TCG Movie Signals Strategic Media Pivot for The Pokémon Company
A new Pokémon movie focused on the TCG is coming in 2027, marking a strategic pivot for the franchise as it navigates massive global fan engagement and logistical challenges.

Apple's AI Pivot: Vision Pro Content Cut, Siri Rebuilt Amid Layoffs
Apple's latest layoffs signal a strategic pivot, dialing back high-cost Vision Pro content while re-tooling Siri for the AI era. What's next for Apple?
Honor Magic 8 Pro vs Samsung Galaxy S26 Ultra: Which Future Flagship Fits Your Wallet and Workflow?
Deciding between the anticipated Honor Magic 8 Pro and Samsung Galaxy S26 Ultra? Our deep dive into expected specs and features provides the fair comparison you need.