Researcher Releases CrowdStrike Falcon Zero-Day Exploit Dubbed 'FalconFlank' for SYSTEM Privileges

CrowdStrike says it is investigating, advises customers to disable Office macro removal policy

edit
By LineZotpaper
Published
Read Time2 min
An anonymous security researcher has published a zero-day privilege escalation exploit targeting CrowdStrike Falcon on fully updated Windows systems, allowing attackers to gain SYSTEM-level access through the endpoint platform's Office malicious macros remediation feature.

The exploit, named FalconFlank, was released this week by a researcher using the handle Nightmare Eclipse. In a GitHub post, the researcher said it works on "a fully updated Windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon" and abuses the Office malicious macros remediation feature in the Falcon sensor. The vulnerability has not yet been assigned a CVE ID.

"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor," the researcher wrote, noting that CrowdStrike may already have detections in place.

In response to BleepingComputer's inquiries, a CrowdStrike spokesperson said the company is actively investigating the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings," the spokesperson said, referring customers to a FalconFlank Tech Alert in the company's support portal. The alert is not publicly accessible.

The release follows several other zero-day exploits published this week by the same researcher, targeting Kaspersky Antivirus, GenDigital Avast Antivirus, and Nvidia. Cybersecurity expert Kevin Beaumont confirmed the privilege escalation exploits released by Nightmare Eclipse.

§

Analysis

Why This Matters

  • The exploit grants SYSTEM privileges on fully updated Windows systems, potentially undermining endpoint protection that many organizations rely on.
  • It affects CrowdStrike Falcon, one of the most widely deployed endpoint security platforms, raising concerns for enterprise customers.
  • The same researcher released multiple zero-days this week, signaling possible broader systemic weaknesses in security software itself.

Background

Zero-day exploits are previously unknown vulnerabilities that have not yet been patched. Privilege escalation to SYSTEM is a critical step for attackers seeking to take full control of a compromised device. CrowdStrike Falcon is a mainstream endpoint detection and response product used by businesses worldwide. The researcher appears to have focused on finding flaws in the very tools designed to protect systems.

Key Perspectives

CrowdStrike: The company says it is investigating the researcher's claims and has issued workaround guidance, advising customers to disable a specific Windows policy setting. It maintains that customers remain protected through other built-in detection mechanisms.

Researcher (Nightmare Eclipse): Claims the exploit works against up-to-date systems and has publicly released proof-of-concept code. The researcher also acknowledged that CrowdStrike may already have detections for the technique.

Critics/Skeptics: The lack of a public advisory and CVE ID makes independent verification difficult. Some may question the timing and motivation of the release, while others may be concerned about the practical impact if the workaround is not implemented.

What to Watch

  • Whether CrowdStrike assigns a CVE ID and releases a permanent patch.
  • Independent validation of the exploit by other security researchers.
  • Any reports of active exploitation in the wild.
  • How the recommended policy change affects existing protection against malicious macros.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.