CrowdStrike Falcon Zero-Day Exploit 'FalconFlank' Unveiled, Granting SYSTEM Privileges
A security researcher known as **Nightmare Eclipse** has publicly released a zero-day exploit, dubbed 'FalconFlank,' targeting **CrowdStrike Falcon** endpoint security. This vulnerability allows for privilege escalation to SYSTEM on fully updated Windows systems, raising immediate concerns for IT security professionals.
An anonymous security researcher operating under the handle **Nightmare Eclipse** has disclosed a zero-day exploit named 'FalconFlank' that impacts **CrowdStrike Falcon** and allows for privilege escalation on current Windows systems.
The vulnerability, which currently lacks a **CVE** ID, reportedly affects devices running the latest versions of **Windows 11** and **Windows Server**, alongside **CrowdStrike**'s endpoint security platform.
Successful exploitation of 'FalconFlank' enables attackers to gain **SYSTEM** privileges by manipulating **CrowdStrike Falcon**'s Office malicious macros remediation feature.
**Nightmare Eclipse** stated, "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique." The researcher confirmed its efficacy on "fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon."
In response to inquiries, a **CrowdStrike** spokesperson confirmed they are actively investigating the claims. They advised customers to disable the **Microsoft Office** Windows policy setting that controls the security software's File Suspicious Macro Removal feature. **CrowdStrike** also directed customers to a **FalconFlank** Tech Alert within its support portal, though this advisory remains inaccessible to the public.
## A String of Zero-Day Disclosures
This week alone, **Nightmare Eclipse** has released a series of other significant zero-day exploits. These include privilege escalation vulnerabilities for **Kaspersky Antivirus for Endpoint** (named **HardBreacher**) and **GenDigital Avast Antivirus** (**PrettyPrague**), as well as a denial-of-service zero-day for **Nvidia** (**GreenSection**) that can crash affected systems.
Cybersecurity expert **Kevin Beaumont** confirmed the authenticity and functionality of these newly released privilege escalation exploits.
Since April, **Nightmare Eclipse** has also disclosed multiple zero-day exploits targeting various **Microsoft** products, including **Microsoft Defender**, **BitLocker**, and other **Windows** components. These include 'LegacyHive,' 'RoguePlanet,' 'BlueHammer,' 'RedSun,' 'YellowKey,' 'GreenPlasma,' 'MiniPlasma,' and 'UnDefend.' While some, like 'LegacyHive' and 'RoguePlanet,' have been patched, others remain unaddressed.
Following the initial zero-day disclosures, **Microsoft** issued a statement regarding "malicious activity causing real harm to our customers," which many interpreted as a veiled threat against the security researcher.