MiniPlasma Windows 0-Day: SYSTEM Shell on Fully-Patched Windows 11 via cldflt.sys Race Condition

Exploit analysis of MiniPlasma: triggering a race condition in cldflt.sys to spawn NT AUTHORITY\SYSTEM shells on fully patched Windows 11.

MiniPlasma Windows 0-Day: SYSTEM Shell on Fully-Patched Windows 11 via cldflt.sys Race Condition
📌
Security Roundup Series: Week of May 28, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: MiniPlasma 0-Day Severity: CVSS 7.8 Status: ⚠️ Zero-Day LPE on Fully Patched Windows 11 Target Component: cldflt.sys Cloud Files Driver

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) published a weaponised proof-of-concept called MiniPlasma on May 18, 2026 — a Windows privilege escalation zero-day that reliably spawns a SYSTEM shell on fully-patched Windows 11 systems running the May 2026 cumulative update. There is no patch available.

Affected Component

The flaw is in cldflt.sys (Windows Cloud Files Mini Filter Driver), specifically in a routine named HsmOsBlockPlaceholderAccess. The root issue was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020. Microsoft issued a supposed fix as part of CVE-2020-17103 in December 2020, but Chaotic Eclipse determined the exact same issue is still present — either the patch was never applied or was silently rolled back.

Technical Details

MiniPlasma exploits a race condition in the Cloud Files filter driver. The original Google Project Zero PoC worked without modification. Chaotic Eclipse weaponised it to execute cmd.exe with SYSTEM privileges.

Security researcher Will Dormann independently confirmed the exploit "reliably" opens a cmd.exe prompt with SYSTEM privileges on Windows 11 systems running the latest May 2026 updates. The exploit does not appear to work on the latest Windows 11 Insider Preview Canary builds, suggesting a fix may be in testing.

Affected Versions

  • All Windows versions with Cloud Files Mini Filter Driver are likely affected.
  • Confirmed working on Windows 11 (all supported versions) as of May 2026 Patch Tuesday.
  • Not working on Windows 11 Insider Preview Canary channel (as of May 2026).
  • Microsoft previously patched a related flaw in the same component in December 2025 (CVE-2025-62221, CVSS 7.8), exploited by unknown threat actors.

Exploitation Requirements

Local access with a standard (non-privileged) user account. The exploit is a race condition, so success rate may vary, but has been reported as reliable in practice.

Remediation

No patch is currently available. Mitigations:

  • Monitor for unexpected SYSTEM-level process spawns from standard user sessions (Windows Event ID 4688 with elevated token).
  • Consider disabling the Windows Cloud Files Mini Filter Driver (cldflt.sys) if OneDrive Files On-Demand and other Cloud Files features are not required. Run: sc stop cldflt && sc config cldflt start= disabled. Note: this will disable OneDrive Files On-Demand.
  • Apply Windows 11 Insider Preview Canary builds on test systems to verify if the forthcoming fix addresses the issue.
  • Detect exploitation attempts by hunting for race condition indicators: rapid handle creation on Cloud Files paths followed by privilege token changes.

← Back to the Security Roundup: Week of May 28, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther