The security researcher known as Nightmare Eclipse — also referred to as Chaotic Eclipse, Infinite Nightmare, and MSNightmare — has dropped a new zero-day exploit called FalconFlank targeting CrowdStrike's Falcon endpoint security platform. The vulnerability is a privilege escalation flaw that abuses the Microsoft Office malicious macros remediation feature in Falcon, a tool that inspects and strips potentially harmful macros from Office documents.
According to the researcher, the proof-of-concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 – Optimal Protection and the malicious macro removal feature enabled.
CrowdStrike acknowledged the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” a CrowdStrike spokesperson told The Register. The company referred customers to the FalconFlank Tech Alert in its support portal.
Security analyst Kevin Beaumont confirmed the exploit works. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.”
FalconFlank follows other recently published vulnerabilities by Nightmare Eclipse, including HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product, and PrettyPrague, a vulnerability in Gen Digital’s Avast antivirus that “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. Beaumont confirmed both HardBreacher and PrettyPrague are working exploits.
Gen Digital acknowledged the Avast vulnerability. “Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges,” the company told The Register. “We immediately initiated our security response procedures and are actively developing a patch.”
Kaspersky did not immediately respond to requests for comment. The researcher also released a memory corruption zero-day for Nvidia called GreenSection, which Beaumont said merely crashes the system. Nvidia did not respond to inquiries.