Security researcher releases exploit for CrowdStrike Falcon, other endpoint security products

Nightmare Eclipse shifts focus from Microsoft to other vendors with zero-day vulnerabilities

edit
By LineZotpaper
Published
Read Time3 min
The prolific zero-day hunter known as Nightmare Eclipse has released a proof-of-concept exploit for a privilege escalation vulnerability in CrowdStrike’s Falcon endpoint security platform, marking a broadening of their focus beyond Microsoft. The researcher has also published exploits for vulnerabilities in Kaspersky and Avast antivirus products, prompting responses from affected vendors.

The security researcher known as Nightmare Eclipse — also referred to as Chaotic Eclipse, Infinite Nightmare, and MSNightmare — has dropped a new zero-day exploit called FalconFlank targeting CrowdStrike's Falcon endpoint security platform. The vulnerability is a privilege escalation flaw that abuses the Microsoft Office malicious macros remediation feature in Falcon, a tool that inspects and strips potentially harmful macros from Office documents.

According to the researcher, the proof-of-concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 – Optimal Protection and the malicious macro removal feature enabled.

CrowdStrike acknowledged the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” a CrowdStrike spokesperson told The Register. The company referred customers to the FalconFlank Tech Alert in its support portal.

Security analyst Kevin Beaumont confirmed the exploit works. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.”

FalconFlank follows other recently published vulnerabilities by Nightmare Eclipse, including HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product, and PrettyPrague, a vulnerability in Gen Digital’s Avast antivirus that “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. Beaumont confirmed both HardBreacher and PrettyPrague are working exploits.

Gen Digital acknowledged the Avast vulnerability. “Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges,” the company told The Register. “We immediately initiated our security response procedures and are actively developing a patch.”

Kaspersky did not immediately respond to requests for comment. The researcher also released a memory corruption zero-day for Nvidia called GreenSection, which Beaumont said merely crashes the system. Nvidia did not respond to inquiries.

§

Analysis

Why This Matters

  • The exploits target widely used endpoint security products, potentially undermining the very tools organizations rely on for protection.
  • The researcher's shift from Microsoft to multiple vendors suggests a broader trend of security product vulnerabilities being exposed, eroding trust in the endpoint security industry.
  • Affected vendors must issue patches quickly; in the meantime, users face a window of exposure if they follow the recommended workarounds.

Background

Nightmare Eclipse has built a reputation for discovering and releasing zero-day vulnerabilities, previously focusing almost exclusively on Microsoft products. The researcher’s recent releases targeting CrowdStrike, Kaspersky, Avast, and Nvidia indicate a deliberate expansion of scope. The exploits are all privilege escalation or memory corruption bugs that could allow attackers to gain elevated system access. The disclosures have been accompanied by working proof-of-concept code, making them immediately usable by malicious actors.

Key Perspectives

CrowdStrike: Advises customers to disable the specific policy setting and relies on cloud-based anti-malware protections. The company has issued a tech alert with further guidance. Kevin Beaumont (security analyst): Confirms the exploits work and calls on cybersecurity vendors to improve product security rather than hyping AI-driven threats. Gen Digital (Avast): Acknowledges the vulnerability, has initiated security response procedures, and is developing a patch. Did not disclose a timeline. Kaspersky and Nvidia: Did not respond to requests for comment as of publication.

What to Watch

  • Patches from CrowdStrike, Kaspersky, Gen Digital, and Nvidia — how quickly they are deployed and whether they fully address the vulnerabilities.
  • Whether Nightmare Eclipse continues to target other endpoint security vendors or expands to different types of security products.
  • Potential regulatory or industry response regarding the security of security products themselves.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.