Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploit Released for Unpatched Windows Vulnerability

Exploit Released for Unpatched Windows Vulnerability

Posted on May 18, 2026 By CWS

A cybersecurity researcher has unveiled an exploit aimed at a Windows vulnerability first identified in 2020, raising concerns that it remains unpatched. The flaw, known as CVE-2020-17103, has a CVSS score of 7.0 and involves a privilege escalation issue within the Windows Cloud Filter driver.

Background on the Vulnerability

Google’s Project Zero researchers initially reported this vulnerability, prompting Microsoft to issue fixes as part of its December 2020 Patch Tuesday updates. The vulnerability allows for registry key manipulation through an undocumented API within the Windows Cloud Filter driver. This can potentially enable an attacker to escalate privileges and execute system code.

The exploit, dubbed MiniPlasma, was recently released by a researcher known as Chaotic Eclipse and Nightmare Eclipse. This exploit takes advantage of the security flaw to generate a System shell, indicating that the issue may not have been adequately patched or that previous fixes were reversed.

Researcher’s Findings and Concerns

According to Chaotic Eclipse, the proof-of-concept code initially provided by Project Zero remains effective, suggesting that the vulnerability persists unpatched. The researcher has also released exploits for other vulnerabilities in Microsoft products, expressing dissatisfaction with Microsoft’s handling of vulnerability disclosures.

Senior principal vulnerability analyst at Tharros Labs, Will Dormann, confirmed that MiniPlasma functions on Windows 11 systems with the May 2026 updates installed. However, it does not seem to be effective on the latest Insider Preview Canary version of Windows 11.

Implications and Future Outlook

The release of such an exploit underscores the importance of timely and thorough patching by software vendors. With the exploit now public, systems running affected Windows versions could be at increased risk. Microsoft has been contacted for comments, but as of now, there is no response. Observers are keenly watching for any updates or further developments from the company.

This incident highlights the ongoing challenges in cybersecurity, particularly the need for proactive measures in addressing vulnerabilities. As the situation evolves, stakeholders are urged to remain vigilant and ensure all systems are up to date with the latest security patches.

Security Week News Tags:Chaotic Eclipse, CVE-2020-17103, Cybersecurity, Exploit, Microsoft, MiniPlasma, Nightmare-Eclipse, privilege escalation, Project Zero, Security, system shell, unpatched flaw, Vulnerability, Windows

Post navigation

Previous Post: Four NPM Packages Found with Malware and DDoS Bot
Next Post: AI Bug Reports Overwhelm Linux Security List

Related Posts

Join the Supply Chain & Risk Summit for Key Insights Join the Supply Chain & Risk Summit for Key Insights Security Week News
Google Patches High-Severity Chrome Vulnerability in Latest Update Google Patches High-Severity Chrome Vulnerability in Latest Update Security Week News
Zip Security Raises .5 Million in Series A Funding Zip Security Raises $13.5 Million in Series A Funding Security Week News
Spectrum Security Secures  Million in Funding Spectrum Security Secures $19 Million in Funding Security Week News
A Security Secures M for Advanced Cyber Defense A Security Secures $37M for Advanced Cyber Defense Security Week News
Reach Security Raises  Million for Exposure Management Solution Reach Security Raises $10 Million for Exposure Management Solution Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark