Update to Bitlocker Zero Day MiniPlasma!



Just like we all knew it would happen (the other shoe dropped), another piece of the Bitlocker encryption has be compromised. 

MiniPlasma is a newly disclosed Windows privilege‑escalation zero‑day that allows a standard user to gain SYSTEM‑level access on fully patched Windows 10 and Windows 11 systems. It is significant because it revives a vulnerability Microsoft believed it fixed years ago — but the underlying flaw appears to have remained exploitable.

MiniPlasma is an exploit targeting the Cloud Filter driver (cldflt.sys), specifically the routine HsmOsBlockPlaceholderAccess. The vulnerability allows an attacker to create arbitrary registry keys inside the .DEFAULT user hive without proper access checks, enabling privilege escalation to SYSTEM.

The exploit was released publicly by the researcher Chaotic Eclipse (Nightmare Eclipse), who also published source code and a compiled PoC on GitHub.

The flaw is essentially the same issue originally reported in 2020 by Google Project Zero’s James Forshaw and assigned CVE‑2020‑17103.

Microsoft claimed to have patched it in December 2020 — but the researcher found the vulnerability still present (or the patch silently rolled back). The exploit works on fully patched Windows 11 Pro (May 2026 updates).

It does not work on the latest Windows 11 Canary Insider build, suggesting Microsoft may have begun addressing it.

MiniPlasma is part of a string of zero‑days released by the same researcher (e.g., BlueHammer, RedSun), reportedly as a protest against Microsoft’s vulnerability‑handling and bug‑bounty processes.

 

Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!

SitusAMC Breached!

Notepad++ update service was compromised