Windows Kernel MiniPlasma Privilege Escalation LPE | MSSP Advisory

Critical
DateMay 17, 2026
📋Executive Summary
Security researcher released working exploit code for MiniPlasma, a Windows privilege escalation zero-day that grants SYSTEM access on fully patched Windows 10 and 11 systems. The vulnerability affects the Windows Kernel and requires local access to exploit, making it a post-compromise escalation tool. Microsoft has not patched this vulnerability and the PoC code is publicly available.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools run with elevated privileges on Windows endpoints, making them prime targets for attackers who gain initial access and then use MiniPlasma to escalate to SYSTEM level control over your management infrastructure. Every Windows client you manage becomes a potential pivot point for attackers to gain administrative control, and you need to warn clients immediately since Microsoft has no patch available.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.