The exploit, named FalconFlank, was released this week by a researcher using the handle Nightmare Eclipse. In a GitHub post, the researcher said it works on "a fully updated Windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon" and abuses the Office malicious macros remediation feature in the Falcon sensor. The vulnerability has not yet been assigned a CVE ID.
"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor," the researcher wrote, noting that CrowdStrike may already have detections in place.
In response to BleepingComputer's inquiries, a CrowdStrike spokesperson said the company is actively investigating the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings," the spokesperson said, referring customers to a FalconFlank Tech Alert in the company's support portal. The alert is not publicly accessible.
The release follows several other zero-day exploits published this week by the same researcher, targeting Kaspersky Antivirus, GenDigital Avast Antivirus, and Nvidia. Cybersecurity expert Kevin Beaumont confirmed the privilege escalation exploits released by Nightmare Eclipse.