CVE detail
CVE-2020-17103
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
ication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in June Patch Tuesday Edition CVE-2026-49160: HTTP.sys Denial of Service Vulnerability Uncontrolled resource consumption in HTTP/2 could allow an unauthenticated attacker to deny service over a network. CVE-2026-45586: Windows Collaborative Translation Framework (
vendorblog.qualys.comJun 9, 2026, 8:52 PM- CVE-2020-17103 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityMicrosoft MSRC
To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems.
vendormsrc.microsoft.comJun 9, 2026, 2:00 PM An old elevation-of-privilege (EoV) vulnerability affecting the Cloud Filter driver “cldflt.sys” in Windows has come back to haunt Microsoft, as researchers claim it is still exploitable six years after it was supposedly patched. The flaw, originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020, was recently picked up by Nightmare […]
newswww.csoonline.comMay 18, 2026, 12:04 PMThe researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.
newswww.securityweek.comMay 18, 2026, 10:38 AM- Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fixSecurity Affairs
MiniPlasma: a Windows SYSTEM privilege escalation believed patched in 2020 (CVE-2020-17103) is still fully working on every patched Windows 11. Once again, security researcher Chaotic Eclipse has released a proof-of-concept exploit for a new Windows privilege escalation zero-day called MiniPlasma, which can grant attackers SYSTEM privileges on fully patched systems. The flaw affects “cldflt.sys,” the […]
newssecurityaffairs.comMay 18, 2026, 8:13 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35771CVSS 7.8 · High
Windows Defender Credential Guard Elevation of Privilege Vulnerability
- CVE-2022-35768CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-35765CVSS 7.8 · High
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35764CVSS 7.8 · High
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35763CVSS 7.8 · High
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35762CVSS 7.8 · High
Storage Spaces Direct Elevation of Privilege Vulnerability