CVE-2020-17103PoC(microsoft / windows_10)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch microsoft windows_10 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10
  • windows_server_2016
  • windows_server_2019

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 54 mentions across 16 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 18 signals
  • PoC mentioned or linked in 31 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 34 signals
  • General: 10 classified signals
  • Peaked 11d ago at 15 mentions (2026-05-18); latest day: 1
  • 54 total mentions across 16 days

Affected systems

Vendors
Products
windows_10windows_server_2016windows_server_2019

7 versions affected across 3 products

Deep dive

Activity timeline54 mentions / 16d
0481115Mentions · 2026-05-14: 1Mentions · 2026-05-15: 3Mentions · 2026-05-16: 13Mentions · 2026-05-17: 3Mentions · 2026-05-18: 15Mentions · 2026-05-19: 6Mentions · 2026-05-20: 3Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-06-01: 1Mentions · 2026-06-10: 1Mentions · 2026-06-24: 1Mentions · 2026-07-14: 1Mentions · 2026-07-22: 1Mentions · 2026-07-23: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 3PoC Mentioned / Linked · 2026-05-16: 12PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-18: 6PoC Mentioned / Linked · 2026-05-19: 3PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-06-01: 1Exploit Tool / Code · 2026-05-15: 2Exploit Tool / Code · 2026-05-16: 5Exploit Tool / Code · 2026-05-17: 1Exploit Tool / Code · 2026-05-18: 5Exploit Tool / Code · 2026-05-19: 2Exploit Tool / Code · 2026-05-20: 1Exploit Tool / Code · 2026-05-22: 1Exploit Tool / Code · 2026-07-14: 1Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-18: 2Patch / Workaround · 2026-05-16: 6Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-18: 8Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 10Technical Details · 2026-05-17: 2Technical Details · 2026-05-18: 11Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-24: 1Technical Details · 2026-06-01: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-22: 105-1405-1505-1605-1705-1805-1905-2005-2105-2205-2406-0106-1006-2407-1407-2207-23
Signal classification6 categories
PoC
2037.0%
Exploit
1018.5%
General
1018.5%
Patch
713.0%
Disclosure
611.1%
Active Exploitation
11.9%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-141
PoC1
2026-05-153
PoC3
2026-05-1613
Exploit1General1Patch1PoC10
2026-05-173
Disclosure1General1PoC1
2026-05-1815
Active Exploitation1Disclosure2Exploit5General3Patch3PoC1
2026-05-196
Disclosure1Exploit2General1Patch1PoC1
2026-05-203
General2PoC1
2026-05-211
Patch1
2026-05-222
Exploit1PoC1
2026-05-241
PoC1
2026-06-011
Disclosure1
2026-06-101
Patch1
2026-06-241
General1
2026-07-141
Exploit1
2026-07-221
Disclosure1
2026-07-231
General1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 Nightmare Eclipse just released another vulnerability called MiniPlasma GitHub: https://github.com/Nightmare-Eclipse/MiniPlasma CVE: CVE-2020-17103 which is a high-severity elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver that allows an attacker to gain elevated, unauthorized access to a targeted system

    Post summary

    Nightmare Eclipse released a PoC for CVE‑2020‑17103, a high‑severity Windows privilege‑escalation flaw, but no active exploitation or patch information was provided.

    81411078926874.8K
    223.7K followersView on X
  • Chaotic Eclipse@ChaoticEclipse0
    PoC

    It's confirmed, CVE-2020-17103 patch is ineffective and the vulnerability still exists, A weaponized PoC can be found here - https://deadeclipse666.blogspot.com/2026/05/miniplasma-powerful-lpe.html Tested against fully patched Windows 11 and Server 2025 machines.

    Post summary

    Text confirms CVE-2020-17103 is still present, cites an ineffective patch, and links to a weaponized PoC.

    7141561431097.4K
    14.5K followersView on X
  • International Cyber Digest@IntCyberDigest
    PoC

    ‼️🚨 Vulnerability researcher Nightmare-Eclipse published MiniPlasma, a Windows local privilege escalation PoC targeting CVE-2020-17103 in cldflt.sys, claiming it can spawn a SYSTEM shell. Microsoft lists the bug as patched since 2020. https://t.co/nNOpDNMLdI

    Post summary

    A researcher disclosed a proof‑of‑concept for CVE‑2020‑17103, a Windows local privilege escalation that can spawn a SYSTEM shell; the vulnerability has been patched by Microsoft since 2020.

    1054152712136.3K
    193.5K followersView on X
  • Andrea P@decoder_it
    Patch

    Turns out that the fix for the CVE-2020-17103 , the Cloud Filter HsmOsBlockPlaceholderAccess driver bug reported by @tiraniddo was never ported to Windows 11 / Server 2025 and still not fixed. LPE from user to SYSTEM 🤦‍♂️ https://t.co/NbwIz7eQcw

    Post summary

    The tweet indicates that the existing patch for CVE‑2020‑17103 has not been applied to Windows 11/Server 2025, leaving the local‑privilege‑escalation flaw unaddressed.

    23611115212.7K
    9.3K followersView on X
  • Co11ateral@co11ateral
    PoC

    Miniplasma (Windows unpatched LPE) CVE-2020-17103 apparently was not patched or the patch was reversed, regardless this the PoC for an LPE in cldflt.sys used to spawn a SYSTEM shell. Success rate may vary since it's a race condition https://github.com/Nightmare-Eclipse/MiniPlasma #windows https://t.co/euvBikD6Ob

    Post summary

    The post announces a publicly available PoC for CVE‑2020‑17103 that exploits an LPE in cldflt.sys via a race condition, noting the patch may not be applied, enabling the creation of a SYSTEM shell.

    0250118516.0K
    8.9K followersView on X
  • Het Mehta@hetmehtaa
    Exploit

    Nightmare-Eclipse dropped another one MiniPlasma is a local privilege escalation in the Cloud Filter driver cldflt.sys it re-uses a race condition in HsmOsBlockPlaceholderAccess that was originally reported as CVE-2020-17103 by James Forshaw six years ago by carefully aborting placeholder hydration the PoC gains the ability to write to arbitrary registry keys this is then used to escalate to a full SYSTEM shell the original Google Project Zero technique works with almost no modifications Microsoft marked this as fixed back in 2020 yet here we are with a working public exploit in 2026 they keep shipping critical drivers with old unaddressed flaws and act surprised when someone actually uses them

    Post summary

    The post reports a functional public exploit for a long‑unpatched Windows Cloud Filter driver, detailing the race‑condition technique and noting Microsoft’s 2020 fix.

    3131491911.6K
    42.2K followersView on X
  • ThreatLocker@ThreatLocker
    Exploit

    Our team confirms the publicly released MiniPlasma exploit for CVE-2020-17103 can elevate a standard Windows user to SYSTEM on fully patched Windows 11 systems. In our testing, Application Allowlisting prevents execution of the exploit payload and remains one of the most effective mitigations against this class of attack. Until an official fix is available, organizations should monitor for attacks by configuring EDR to monitor for modifications to: \Registry\User\Software\Policies\Microsoft\CloudFiles\BlockedApps* and \Registry\User\.DEFAULT\Volatile Environment* The exploit targets the Windows Cloud Filter driver (cldflt.sys) and appears to revive a vulnerability originally reported in 2020. https://vimeo.com/1193389530

    Post summary

    A publicly released MiniPlasma exploit for CVE‑2020‑17103 can elevate privileges on fully patched Windows 11 systems; the article highlights mitigation via Application Allowlisting and EDR monitoring, while noting that an official patch is pending.

    1611482.1K
    2.8K followersView on X
  • Sergio de los Santos@ssantosv
    PoC

    Más. El investigador enfadado con Microsoft suelta "Miniplasma" una variante de su última elevación, encontrada por accidente y que parece una vuelta de CVE-2020-17103. Según él "eliminaron el parche en algún momento" porque la PoC original de 2020 funciona hoy. La ha mejorado.

    Post summary

    A frustrated researcher released an updated PoC called "Miniplasma" for CVE‑2020‑17103, noting that the original PoC remains effective after patch removal.

    0602002.1K
    17.9K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2020-17103 was apparently not patched or the patch was reversed, regardless this the PoC for an LPE in cldflt.sys https://github.com/Nightmare-Eclipse/MiniPlasma

    Post summary

    CVE-2020-17103 remains unpatched; a PoC for a local privilege escalation in cldflt.sys is available at the linked GitHub repository.

    0201321.8K
    158.6K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Picus Security notes that MiniPlasma is a high-severity zero-day on Windows 11 and Server 2022/2025, enabling SYSTEM access via CVE-2020-17103 and thread token impersonation. https://www.picussecurity.com/resource/blog/the-return-of-a-ghost-unpacking-the-miniplasma-zero-day-exploit

    Post summary

    Picus Security publicly discloses the MiniPlasma zero‑day (CVE‑2020‑17103), describing a privilege‑escalation flaw that grants SYSTEM access on Windows 11 and Server 2022/2025 through thread token impersonation.

    02072885
    22.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Exploit

    📍 ثغرة Windows جديدة باسم MiniPlasma تعطي صلاحيات SYSTEM، والـ الاستغلال تم نشره من قبل الباحث. القصة هنا مرتبطة بثغرة قديمة من 2020 برقم (CVE-2020-17103) اكتشفها James Forshaw من Google Project Zero في سبتمبر 2020، ومايكروسوفت قالت إنها أصلحتها في ديسمبر 2020. Project Zero قالو ان Microsoft أصلحت عدة ثغرات في Cloud Filter و WOF drivers في ديسمبر 2020، من بينها CVE-2020-17103. 📍 في 13 مايو 2026، الباحث Chaotic Eclipse، المعروف أيضاً باسم Nightmare-Eclipse، نشر استغلال باسم MiniPlasma على GitHub. الباحث يقول إن نفس المشكلة ما زالت قابلة للاستغلال على أنظمة ويندوز المحدثة، إما لأن الإصلاح القديم ما كان كافي، أو لأن السلوك الضعيف رجع في تحديث لاحق. ⚙️ الثغرة في cldflt.sys وهذا هو Windows Cloud Files Mini Filter Driver، المكوّن المسؤول عن Cloud Files وملفات الـ placeholder المستخدمة مع OneDrive وخدمات السحابة. 📍 فكرة الاستغلال باختصار: المهاجم يحتاج وصول محلي بحساب مستخدم عادي. يعني هذه ليست ثغرة تستغل عن بعد او تسمح بالوصول الاولي للشبكه من خلال الانترنت. لكن إذا المهاجم دخل الجهاز كمستخدم عادي، الـثغره ممكن تساعده في تصعيد صلاحياته إلى SYSTEM. وهذا الشي لايقلل من خطورة الثغرة في Windows، لأنه يعطي قدرة أعلى على تنفيذ أوامر، تثبيت أدوات، محاولة تعطيل حماية، أو التحرك داخل الجهاز. ⚙️ الـ exploit يستغل race condition حول طريقة تعامل Cloud Filter driver مع Registry access أثناء عمليات مرتبطة بالـ placeholder hydration.

    Post summary

    باحث نشر استغلال MiniPlasma متاح على GitHub يركز على رفع صلاحيات محليًا عبر race condition في driver Cloud Filter، مع إشارة إلى أن Microsoft أصلحت CVE‑2020‑17103 في ديسمبر 2020.

    010641.3K
    50.0K followersView on X
  • mRr3b00t@UK_Daniel_Card
    PoC

    More fun: MS exchange: https://www.cve.org/CVERecord?id=CVE-2026-42897 Windows: MiniPlasma PoC ITW CVE-2020-17103 maybe wasn't actually patched quite so well..... happy weekend cyber tweeps! https://github.com/Nightmare-Eclipse/MiniPlasma

    Post summary

    The tweet highlights the availability of a MiniPlasma proof‑of‑concept for CVE-2026-42897 and links to its GitHub repository, but offers no discussion of active exploitation, patches, or technical details.

    110531.4K
    124.1K followersView on X
  • DFIR Radar@DFIR_Radar
    General

    Chaotic Eclipse reveals MiniPlasma privilege escalation affecting Windows 11 - CVE-2020-17103 supposedly patched in 2020 mysteriously remains exploitable on latest builds. #DFIR_Radar https://t.co/KxCUPlxBWa

    Post summary

    The tweet highlights that CVE‑2020‑17103, once thought patched in 2020, remains exploitable on recent Windows 11 builds via a MiniPlasma privilege escalation, but provides no proof of ongoing exploitation or PoC details.

    10041602
    1.8K followersView on X
  • 💜S u m i ~ 🇨🇴@Koto_Sumire
    General

    @realazureangel @nathans_codes_2 CVE-2026-32202, CVE-2020-17103, Eternal Blue/Romance wants you. https://x.com/vxunderground/status/2055556704998138251 https://t.co/DxSDHIrqix

    Post summary

    The tweet merely lists CVE identifiers and a historical exploit name without providing technical details, exploitation evidence, or mitigation information.

    10040348
    529 followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @ChaoticEclipse0 CVE-2020-17103 patch has been confirmed ineffective - a weaponized PoC is now public and verified on the latest patched Microsoft systems. This is a 2020 CVE. Still not fixed in 2026. http://vulntracker.io

    Post summary

    A weaponized proof‑of‑concept for CVE‑2020‑17103 is publicly available and has been verified against the latest patched Microsoft systems, indicating the patch remains ineffective.

    01022213
    653 followersView on X
  • yousukezan@yousukezan
    PoC

    Windows の Cloud Files Mini Filter Driverの権限昇格 CVE-2020-17103 がまだ動作するらしい https://github.com/Nightmare-Eclipse/MiniPlasma

    Post summary

    The post indicates CVE‑2020‑17103, a privilege escalation flaw in the Windows Cloud Files Mini Filter Driver, is still operational and links to a GitHub repository that presumably hosts a proof‑of‑concept, but no details of a functional exploit or active attacks are provided.

    000411.4K
    14.5K followersView on X
  • SCYTHE@scythe_io
    Exploit

    CVE-2020-17103 takes a standard user to SYSTEM through http://cldflt.sys with no UAC prompt, and the driver ships active on every modern Windows machine. Register here: https://hubs.ly/Q04p8vSn0 to see Trey Bilbrey (@TCraf7) and Tyler Casey demo MiniPlasma-Runner live and walk through where defenders can catch it. July 23 | 12:00 PM ET #ThreatThursdayLive #CybersecurityEvents #MiniPlasma

    Post summary

    CVE‑2020‑17103 enables a standard user to gain SYSTEM privileges through http://cldflt.sys without a UAC prompt, and this exploitation method is demonstrated live by the MiniPlasma‑Runner tool; no patch or evidence of in‑the‑wild attacks are mentioned.

    01021313
    6.9K followersView on X
  • Andrea P@decoder_it
    Patch

    Server 2019 before patch (CVE-2020-17103 , december 8th 2020) is vulnerable, after patch not. The patch was ported on 2022 too

    Post summary

    The statement notes that Windows Server 2019 was vulnerable to CVE‑2020‑17103 until a patch was applied, and that the patch was later ported in 2022.

    00031864
    9.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    6 yıl önce Microsoft'a bildirilen yetki yükseltme açığı halen aynı şekilde duruyor iddiası var. 2020 yılında bildiriliyor ve sözde CVE-2020-17103 olarak fixleniyor, ancak açığının halen var olduğu söylenmekte. Windows 11 ve Server 2025 de test edilmiş. https://github.com/Nightmare-Eclipse/MiniPlasma

    Post summary

    The post asserts that CVE‑2020‑17103, a privilege‑escalation flaw, remains active and shares a GitHub repository that likely contains a PoC, while noting that a patch was released but may not have fully mitigated the vulnerability.

    00031219
    1.2K followersView on X
  • SCYTHE@scythe_io
    Disclosure

    CVE-2020-17103 escalates a standard user to SYSTEM through http://cldflt.sys with no UAC prompt, and the driver ships active on every Windows 10 and 11 machine. Register here: https://hubs.ly/Q04pBS7G0 and join us tomorrow as @TCraf7 and Tyler Casey break it down live and cover where to catch it. July 23 | 12:00 PM ET #ThreatThursdayLive #CybersecurityEvents #MiniPlasma

    Post summary

    The message discloses that CVE-2020-17103 enables privilege escalation to SYSTEM without UAC, noting the driver is present on all Windows 10/11 machines, but does not mention exploitation, patches, or PoC code.

    01011220
    6.9K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10---
OSmicrosoftwindows_101803--
OSmicrosoftwindows_101809--
OSmicrosoftwindows_101903--
OSmicrosoftwindows_101909--
OSmicrosoftwindows_102004--
OSmicrosoftwindows_1020h2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_20161903--
OSmicrosoftwindows_server_20161909--
OSmicrosoftwindows_server_20162004--
OSmicrosoftwindows_server_201620h2--
OSmicrosoftwindows_server_2019---

Explore more