New Windows MiniPlasma Zero Day Exploit Gives SYSTEM Access
Windows just got a fresh local privilege escalation zero day that lets attackers grab SYSTEM on fully patched machines.
The flaw sits in cldflt.sys, the Windows Cloud Files Mini Filter Driver. The exploit abuses the undocumented CfAbortHydration API to create arbitrary registry keys without access checks, spawning a SYSTEM shell from a standard user account. Public PoC released on GitHub by researcher Chaotic Eclipse.
Same bug Google Project Zero reported in 2020 as CVE-2020-17103. Microsoft supposedly patched it that December, but the original PoC still works unmodified.
BleepingComputer confirmed the exploit works on a fully patched Windows 11 Pro running the May 2026 Patch Tuesday updates.
