‘The exact same issue that was reported to Microsoft by Google project zero is actually still present, unpatched’: Chaotic Eclipse strikes again with another worrying Windows security flaw



  • Researcher Chaotic Eclipse discloses new Windows 11 zero‑day affecting the Cloud Filter driver
  • MiniPlasma, originally tracked as CVE‑2020‑17103, was reported years ago but remains exploitable despite prior patch attempts
  • It is the sixth vulnerability leaked by the researcher, highlighting ongoing disputes with Microsoft’s handling of bug reports

Threat actors could escalate privileges and gain SYSTEM access on a fully patched Windows 11 device thanks to an unpatched vulnerability which allegedly should have been fixed years ago, new reports have claimed.

A researcher with the alias Chaotic Eclipse recently disclosed a Proof-of-Concept (PoC) exploit for a zero-day vulnerability they named “MiniPlasma”. In a new GitHub entry, the researcher said the bug impacts the ‘cldflt.sys’ Cloud Filter driver and its ‘HsmOsBlockPlaceholderAccess’ routine.

https://cdn.mos.cms.futurecdn.net/RWhH3kdDmedMKGmAzdyrvH-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img