Find notable cyber news and cases, enriched with sources, timelines, and signals.

Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw

Vulnerability
First reported
Last updated
Happening score
H score 52
2 unique sources, 2 articles

Summary

Hide ▲

MiniPlasma is a Windows privilege-escalation zero-day in cldflt.sys that can give attackers SYSTEM privileges on fully patched Windows systems. The flaw affects the Windows Cloud Files Mini Filter Driver and is described as still unpatched despite an earlier assumption that Microsoft had fixed it. A public proof-of-concept now shows reliable local elevation on current Windows builds, making the issue immediately relevant to defenders.

Related Happenings

Windows cldflt.sys privilege escalation (CVE-2020-17103)

Vulnerability
First: 18.05.2026 01:30 Last: 18.05.2026 01:30 Sources 1

About this happening: A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...

Azure Backup for AKS privilege escalation flaw

Vulnerability
First: 16.05.2026 23:55 Last: 16.05.2026 23:55 Sources 1

About this happening: A **critical Azure Backup for AKS** privilege-escalation flaw was independently validated, exposing Kubernetes clusters to **cluster-admin** takeover from the low-privileged **Bac...

Microsoft Edge stops loading saved passwords into cleartext memory at startup

Security Tool/Service
First: 15.05.2026 17:49 Last: 15.05.2026 17:49 Sources 1

About this happening: **Microsoft Edge** is changing its built-in password manager so **saved passwords** are no longer loaded into **process memory in clear text** at startup, reducing the risk of loc...

Microsoft adds Cloud-Initiated Driver Recovery for Windows Update driver rollbacks

Security Tool/Service
First: 15.05.2026 15:29 Last: 15.05.2026 15:29 Sources 1

About this happening: Microsoft is adding **Cloud-Initiated Driver Recovery** to **Windows Update**, giving it a remote rollback control for **problematic Windows drivers**. The capability reduces how...

Windows 11 BitLocker bypass YellowKey security flaw

Vulnerability
First: 14.05.2026 10:27 Last: 14.05.2026 10:27 Sources 1

About this happening: **YellowKey** is a **Windows BitLocker security feature bypass** tracked as **CVE-2026-45585** that can expose **BitLocker-protected drives** through the **Windows Recovery Enviro...

Latest development: 20.05.2026 10:31

Microsoft assigned CVE-2026-45585 to YellowKey, a Windows BitLocker security feature bypass, and recommended removing autofstx.exe from the Session Manager BootExecute REG_MULTI_SZ value, reestablishing BitLocker trust for WinRE, and moving already encrypted devices from TPM-only to TPM+PIN to require a pre-boot PIN.

Timeline

  1. 18.05.2026 07:59 3 articles · 9d ago

    Initial report: Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw

    Initial Disclosure

    A public **PoC** now turns **MiniPlasma** into a **SYSTEM**-level Windows privilege-escalation path in **cldflt.sys**. The flaw is described as still **unpatched** and may affect **all Windows versions**.

    Show sources