A new zero-day exploit called MiniPlasma grants SYSTEM access on fully patched Windows 11 systems. The exploit targets a flaw in the Cloud Filter driver cldflt.sys. That vulnerability was originally reported as CVE-2020-17103.
Exploit targets Cloud Filter driver
Researcher Chaotic Eclipse published the exploit. BleepingComputer and security expert Will Dormann confirmed it works. Chaotic Eclipse ran an unmodified proof-of-concept from researcher James Forshaw and reported it worked as is.
Chaotic Eclipse expressed uncertainty about the patch status. The researcher wrote: "I'm unsure if Microsoft just never patched the issue or the patch was silently rolled back at some point for unknown reasons." Microsoft has not commented on the disclosure.
The exploit is part of a series of Windows zero-day disclosures by Chaotic Eclipse. The company has not confirmed whether it will issue a fix outside the regular update cycle.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.