
CVE-2020-17103
A Windows Local Privilege Escalation Zero-Day
Turning placeholder files into SYSTEM access
MiniPlasma is a powerful local privilege escalation exploit targeting CVE-2020-17103 in the Windows Cloud Files Mini Filter Driver (cldflt.sys).
It allows any standard user to escalate to NT AUTHORITY\SYSTEM privileges on fully patched Windows 11, Windows Server 2022, and Windows Server 2025 systems (as of June 2026).
| Operating System | Supported |
|---|
Note: Does not work on the latest Windows 11 Insider Canary builds.
cldflt.sys (Cloud Files Mini Filter Driver)HsmOsBlockPlaceholderAccess
cldflt.sys activityMade with ❤️ for the security community
Stay safe. Patch early. Patch often.
| Patch Status |
|---|
| Windows 11 (all versions) | Yes | Unpatched |
| Windows Server 2022 | Yes | Unpatched |
| Windows Server 2025 | Yes | Unpatched |
| Windows 10 | Partial | Varies |