The MiniPlasma Windows zero-day is a serious reminder that endpoint compromise does not end at initial access. Once an attacker gains a foothold on a Windows system, local privilege escalation flaws can turn limited access into full SYSTEM-level control, allowing deeper persistence, credential theft, security-tool tampering, and lateral movement. This is different from Tycoon2FA’s Microsoft 365 device-code phishing, which targets cloud account access through social engineering. MiniPlasma targets the endpoint privilege model itself.

Organizations should monitor for unusual local privilege escalation behavior, restrict local admin rights, harden endpoint detection controls, and treat any low-privilege compromise as potentially serious until fully investigated. Security teams should also watch Microsoft guidance closely, because proof-of-concept release often shortens the time between disclosure and real-world abuse. Attackers do not need every vulnerability to be remote; sometimes they just need one user session and a privilege-escalation bug to turn a workstation into a launchpad.


A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems. [...]

Source: New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released via Bleeping Computer — published 17 May 2026.