INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Chaotic Eclipse Exploit MiniPlasma Zero-Day

| 2026-05-18 08:13 CRITICAL HIGH
Executive Summary AI-generated
The latest incident data reveals a critical vulnerability in Windows, dubbed MiniPlasma. This zero-day exploit can grant attackers SYSTEM privileges on fully patched systems, compromising the security of millions of users worldwide. The flaw affects "cldflt.sys," a key component of the Cloud Files Mini Filter Driver, and is linked to a 2020 Microsoft security fix that was allegedly missed or undone. Experts have confirmed the vulnerability through proof-of-concept exploits for both MiniPlasma and GreenPlasma, two previously undisclosed Windows privilege escalation zero-days. The issue has sparked concerns about delayed updates and potential patch failures, with some researchers questioning whether the latest Insider Preview Canary build addresses it.
Technical Mitigations AI-generated
* Implement a patching schedule: Regularly update and patch Windows systems to ensure that any known vulnerabilities are addressed before they can be exploited. * Use secure coding practices: Implement secure coding practices, such as input validation and sanitization, to prevent exploitation of zero-day vulnerabilities like MiniPlasma. * Monitor system logs for suspicious activity: Continuously monitor system logs for signs of malicious activity, including attempts to spawn SYSTEM shells or execute arbitrary code. * Implement a sandboxing mechanism: Use sandboxes or virtual machines to isolate sensitive systems and applications from potential exploits, reducing the risk of successful attacks. * Regularly review patch notes and update history: Carefully review patch notes and update histories for any known vulnerabilities that have been patched in previous versions of Windows.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825 CVE-2020-17103CVE-2020-17103 CVE-2025-62221CVE-2025-62221
Target & Sectors
Global Scope
Incident Timeline
‎2020/05/19
Threat actors exploited a previously unknown vulnerability in GreenPlasma's MiniPlasma Windows zero-day exploit.
organisation GreenPlasma
‎September 2020
Threat actors exploited a previously unknown vulnerability in the Cloud Filter driver, cldflt.sys.
organisation Google Project Zero
organisation Microsoft
observable cldflt.sys
‎December 2020
Threat actors used a previously reported vulnerability to target the Chaotic Eclipse platform.
vulnerability CVE-2020-17103
organisation Chaotic Eclipse
organisation Microsoft Patch
‎December 2025
Threat actors exploited a privilege escalation flaw in the same component.
tactic Privilege Escalation
vulnerability CVE-2025-62221
organisation CVSS
general_metric 7.8 same component
‎April 10
Attackers began using BlueHammer on April 10.
‎April 16
Attackers began using BlueHammer on April 10, then moved to the proof-of-concept code for RedSun and UnDefend.
‎2022/2026
Threat actors exploited a zero-day vulnerability in the Windows Collaborative Translation Framework, enabling privilege escalation on vulnerable versions of Windows.
tactic Privilege Escalation
infrastructure Windows
general_metric 11 patched Windows
organisation the Windows Collaborative Translation Framework
organisation CTFMON
tactic T1584.004 - Server
‎2022/2025
Threat actors exploited a previously unknown vulnerability in Windows 11 and Server 2022/2025 systems to gain access to locked drives protected by TPM-only BitLocker configurations.
infrastructure Windows
general_metric 11 patched Windows
tactic T1584.004 - Server
organisation BitLocker
infrastructure 10 Server
general_metric 10 Windows
‎May 18, 2026 Zero Day
Chaotic Eclipse released a proof-of-concept exploit for a Windows zero-day vulnerability that grants attackers SYSTEM privileges on fully patched systems.
tactic Privilege Escalation
infrastructure Windows
organisation GreenPlasma
organisation YellowKey
organisation PoC
general_metric 0 Day
‎May 18, 2026
Threat actors exploited a previously unknown vulnerability in MiniPlasma Windows to gain unauthorized access.
‎2026/05/18
The exploit works in the latest public version of Windows 11.
infrastructure Windows
infrastructure 2020 fix MiniPlasma
organisation MiniPlasma
organisation Forshaw
organisation CVE-2026-33825
organisation BlueHammer
organisation google
organisation the Insider Preview Canary
organisation Insider Preview Canary Windows
organisation YellowKey
organisation Security Affairs
organisation the Windows Recovery Environment
organisation WinRE
organisation Insider Preview Canary Windows 11
organisation PoC
organisation Tharros
organisation API
organisation GreenPlasma
organisation Microsoft
organisation GitHub
organisation Nightmare
organisation Nightmare-Eclipse
organisation RedSun
organisation Microsoft Defender
organisation Huntress
organisation USB
organisation EFI
organisation SecurityAffairs
‎May 2026
Threat actors used a previously unknown vulnerability in fully patched Windows 11 systems running the latest May 2026 updates to target and exploit cmd.exe with SYSTEM privileges.
infrastructure Windows
general_metric 11 patched Windows
organisation MiniPlasma
observable cmd.exe
organisation Mastodon
organisation BleepingComputer
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,020
Fix Miniplasma
Metrics
infrastructure
10
Server