MiniPlasma Windows Privilege Escalation Zero-Day | MSSP Advisory
Critical
DateMay 18, 2026
📋Executive Summary
A Windows privilege escalation zero-day called MiniPlasma allows attackers to gain SYSTEM privileges on fully patched Windows systems by exploiting the Windows Cloud Files Mini Filter Driver (cldflt.sys). Security researcher Chaotic Eclipse released proof-of-concept code for this vulnerability. The attack grants the highest level of Windows privileges on current systems with all patches applied.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools run with elevated privileges on Windows endpoints, making them prime targets for this privilege escalation attack once an attacker has initial access. Every Windows client you manage becomes a potential SYSTEM-level compromise risk, and you need to advise clients immediately since this affects fully patched systems where they think they are protected.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.