🛡️ MiniPlasma - CVE-2020-17103

A Windows Local Privilege Escalation Zero-Day
Turning placeholder files into SYSTEM access
📋 Overview
MiniPlasma is a powerful local privilege escalation exploit targeting CVE-2020-17103 in the Windows Cloud Files Mini Filter Driver (cldflt.sys).
It allows any standard user to escalate to NT AUTHORITY\SYSTEM privileges on fully patched Windows 11, Windows Server 2022, and Windows Server 2025 systems (as of June 2026).
🎯 Affected Systems
| Operating System | Supported | Patch Status |
|---|
| Windows 11 (all versions) | Yes | Unpatched |
| Windows Server 2022 | Yes | Unpatched |
| Windows Server 2025 | Yes | Unpatched |
| Windows 10 | Partial | Varies |
Note: Does not work on the latest Windows 11 Insider Canary builds.
🔍 Technical Details
- CVE: CVE-2020-17103
- Component:
cldflt.sys (Cloud Files Mini Filter Driver)
- Vulnerable Function:
HsmOsBlockPlaceholderAccess
- Exploit Type: Race condition + Token manipulation
- Researcher: Chaotic Eclipse (Nightmare-Eclipse)
How It Works (Simplified)
- Triggers placeholder file hydration operations (OneDrive-style files)
- Manipulates impersonation tokens (valid ↔ anonymous)
- Races kernel access checks
- Achieves arbitrary code execution as SYSTEM
⚠️ Impact
- Privilege Escalation: User → SYSTEM
- No admin rights required
- Works from standard user context
- Bypasses most EDR assumptions
- Extremely dangerous in enterprise environments
🛠️ Mitigation & Recommendations
- Apply the next Microsoft Patch Tuesday update immediately
- Disable Cloud Files / OneDrive placeholder files where possible
- Use strict Application Control (WDAC / AppLocker)
- Monitor for suspicious
cldflt.sys activity
- Follow least-privilege principles
📚 References
- Original Project Zero Report (2020)
- MiniPlasma Public PoC Release (May 2026)
- Microsoft Security Response
Made with ❤️ for the security community
Stay safe. Patch early. Patch often.