CrowdStrike FalconFlank Zero-Day Vulnerability Exploits System Privileges

www.news4hackers.com-crowdstrike-falconflank-zero-day-vulnerability-exploits-system-privileges-crowdstrike-falconflank-zero-day-vulnerability-exploits-system-privileges

New vulnerability in CrowdStrike Falcon enables privilege escalation on patched Windows systems

Vulnerability Overview

An anonymous cybersecurity researcher operating under the alias Nightmare Eclipse has disclosed a previously unknown vulnerability in CrowdStrike Falcon, a widely used endpoint security solution. The flaw, designated FalconFlank, allows threat actors to gain SYSTEM-level access on systems running the most recent versions of Windows 11 and Windows Server, as well as the CrowdStrike Falcon platform.

The Exploit Mechanism

The exploit leverages a specific feature within CrowdStrike Falcon’s Office malicious macros remediation process to execute commands with elevated privileges. Nightmare Eclipse revealed that the vulnerability exploits the Office malicious macros remediation functionality in the Falcon Sensor. The researcher emphasized that the exploit would likely be detected by CrowdStrike’s existing security measures, advising potential testers to either add the payload to exclusion lists or modify the proof-of-concept code to evade detection.

CrowdStrike’s Response

According to the disclosure, the flaw is effective on fully updated Windows 11 25H2 and Windows Server 2025 systems equipped with CrowdStrike Falcon. A representative from CrowdStrike confirmed the existence of the vulnerability and stated the company is actively investigating the claims. The spokesperson recommended customers disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while emphasizing that protection remains available through Cloud Anti-malware for Microsoft Office Files configurations. The company directed affected users to a non-public technical alert hosted on its support portal.

Context of Other Exploits

This disclosure follows the release of multiple other zero-day exploits by Nightmare Eclipse, including a privilege escalation flaw targeting Kaspersky Antivirus for Endpoint (HardBreacher), a similar vulnerability in GenDigital Avast Antivirus (PrettyPrague), and a denial-of-service flaw affecting Nvidia (GreenSection). Cybersecurity analyst Kevin Beaumont verified the authenticity of these exploits, confirming their operational effectiveness.

Researcher’s History

The researcher has previously exposed critical vulnerabilities in Microsoft products since April, including flaws in Microsoft Defender, BitLocker, and various Windows components. These vulnerabilities, collectively referred to as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, have varying statuses. While some have been resolved, others remain unpatched.

Microsoft’s Response

Microsoft’s response to earlier disclosures included warnings about legal action against individuals engaging in “malicious activity causing real harm to customers,” which some interpreted as a direct threat to the researcher.

Industry Challenges

Data from the Blue Report 2026 highlights that 37% of attacker activities are blocked when valid credentials are compromised, underscoring persistent challenges in endpoint security. The incident underscores ongoing challenges in securing enterprise environments against sophisticated threats that exploit trusted system components. As organizations continue to adopt advanced security solutions, the discovery of such vulnerabilities highlights the need for continuous monitoring and adaptive defense strategies.

According to the disclosure, the flaw is effective on fully updated Windows 11 25H2 and Windows Server 2025 systems equipped with CrowdStrike Falcon.

A representative from CrowdStrike confirmed the existence of the vulnerability and stated the company is actively investigating the claims.


Blog Image

About Author

en_USEnglish