MiniPlasma, a Powerful LPE
A new local privilege escalation (LPE) exploit named MiniPlasma has been discovered, targeting a missing patch for CVE-2020-17103 in Windows systems. The proof-of-concept successfully executed a SYSTEM shell on fully patched Windows 11 and Windows Server 2025. The vulnerability appears to be present in the cldflt.sys driver.
- ▪MiniPlasma exploits a missing patch for CVE-2020-17103 in Windows systems.
- ▪The exploit was tested successfully on fully patched Windows 11 and Windows Server 2025.
- ▪It achieves local privilege escalation by targeting the cldflt.sys driver.
- ▪The proof-of-concept code is publicly available on GitHub.
- ▪The discovery was shared with a PGP-signed message verifying authenticity.
Opening excerpt (first ~120 words) tap to expand
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA512This one is accidental, I didn't even think cldflt.sys had that vulnerability. Turns out CVE-2020-17103 patch is just not present at all ?The new PoC was tested against fully patched Windows 11 and Windows Server 2025 and managed to flawlessly spawn a SYSTEM shell.https://github.com/Nightmare-Eclipse/MiniPlasma-----BEGIN PGP SIGNATURE-----iHUEARYKAB0WIQRJTvAf/AWVhAKEeb7FFoRCS0/SbAUCaggLWQAKCRDFFoRCS0/SbHKSAP4/bkKYCDTKZvq5WoUsWKuYgWBvlfun8KYJtNgYREezVAEAj8cg30PjcjcuREzr4eniahPoc6bleEEos0PwVOUa5AA==oct9-----END PGP SIGNATURE-----
Excerpt limited to ~120 words for fair-use compliance. The full article is at Blogspot.