MiniPlasma Windows 0-Day: SYSTEM Shell on Fully-Patched Windows 11 via cldflt.sys Race Condition
Exploit analysis of MiniPlasma: triggering a race condition in cldflt.sys to spawn NT AUTHORITY\SYSTEM shells on fully patched Windows 11.
MiniPlasma 0-Day
Severity: CVSS 7.8
Status: ⚠️ Zero-Day LPE on Fully Patched Windows 11
Target Component: cldflt.sys Cloud Files Driver
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) published a weaponised proof-of-concept called MiniPlasma on May 18, 2026 — a Windows privilege escalation zero-day that reliably spawns a SYSTEM shell on fully-patched Windows 11 systems running the May 2026 cumulative update. There is no patch available.
Affected Component
The flaw is in cldflt.sys (Windows Cloud Files Mini Filter Driver), specifically in a routine named HsmOsBlockPlaceholderAccess. The root issue was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020. Microsoft issued a supposed fix as part of CVE-2020-17103 in December 2020, but Chaotic Eclipse determined the exact same issue is still present — either the patch was never applied or was silently rolled back.
Technical Details
MiniPlasma exploits a race condition in the Cloud Files filter driver. The original Google Project Zero PoC worked without modification. Chaotic Eclipse weaponised it to execute cmd.exe with SYSTEM privileges.
Security researcher Will Dormann independently confirmed the exploit "reliably" opens a cmd.exe prompt with SYSTEM privileges on Windows 11 systems running the latest May 2026 updates. The exploit does not appear to work on the latest Windows 11 Insider Preview Canary builds, suggesting a fix may be in testing.
Affected Versions
- All Windows versions with Cloud Files Mini Filter Driver are likely affected.
- Confirmed working on Windows 11 (all supported versions) as of May 2026 Patch Tuesday.
- Not working on Windows 11 Insider Preview Canary channel (as of May 2026).
- Microsoft previously patched a related flaw in the same component in December 2025 (CVE-2025-62221, CVSS 7.8), exploited by unknown threat actors.
Exploitation Requirements
Local access with a standard (non-privileged) user account. The exploit is a race condition, so success rate may vary, but has been reported as reliable in practice.
Remediation
No patch is currently available. Mitigations:
- Monitor for unexpected SYSTEM-level process spawns from standard user sessions (Windows Event ID 4688 with elevated token).
- Consider disabling the Windows Cloud Files Mini Filter Driver (
cldflt.sys) if OneDrive Files On-Demand and other Cloud Files features are not required. Run:sc stop cldflt && sc config cldflt start= disabled. Note: this will disable OneDrive Files On-Demand. - Apply Windows 11 Insider Preview Canary builds on test systems to verify if the forthcoming fix addresses the issue.
- Detect exploitation attempts by hunting for race condition indicators: rapid handle creation on Cloud Files paths followed by privilege token changes.
← Back to the Security Roundup: Week of May 28, 2026