Windows Vulnerability MiniPlasma Unfixed Since 2020 CVE-2020-17103

Microsoft Windows faces scrutiny over the MiniPlasma vulnerability (CVE-2020-17103), a privilege escalation flaw that should have been fixed six years ago.

Windows Vulnerability MiniPlasma Unfixed Since 2020 CVE-2020-17103

Microsoft is facing scrutiny over a security vulnerability that should have been resolved years ago. The issue, identified as CVE-2020-17103, involves a privilege escalation flaw originally discovered by James Forshaw of Google Project Zero. The vulnerability was first reported six years prior to the current announcement date of May 16, 2021.

Privilege escalation flaw originally patched in 2020 remains active today

The flaw has been given the name MiniPlasma by researcher Nightmare-Eclipse. It allows an attacker to execute a shell with SYSTEM privileges on the affected system. The exploit relies on a race condition, which means its success rate varies depending on the specific environment and timing.

Google Project Zero previously published a proof of concept for this vulnerability that works without modification. Microsoft had patched this issue under CVE-2020-17103 in the past. Reports indicate that the patch may have been either unapplied or secretly rolled back by the vendor.

The current situation highlights a gap in the maintenance of long-patched security issues. The recurrence of a six-year-old exploit suggests potential failures in the update deployment process. This raises questions about the reliability of Windows security updates for older vulnerabilities.

It remains unclear whether Microsoft simply failed to apply the patch or rolled it back for some reason. The vendor has not confirmed the specific cause of the vulnerability's reappearance. The exact scope of systems affected by this rollback or omission is not yet defined.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion