Cybersecurity

FalconFlank Exploit Claims to Grant SYSTEM Privileges via CrowdStrike Falcon

An anonymous security researcher using the name Nightmare Eclipse disclosed a zero-day exploit called FalconFlank, claiming that it elevates privileges on updated Windows versions by exploiting CrowdStrike Falcon’s feature for removing suspicious macros. CrowdStrike is investigating the claim and has temporarily advised customers to disable a specific setting while keeping another protection enabled.

2026-09-04
3 min read
6 views
فريق تحرير certi.news
FalconFlank Exploit Claims to Grant SYSTEM Privileges via CrowdStrike Falcon

An anonymous security researcher using the pseudonym Nightmare Eclipse published an exploit called FalconFlank, claiming that it exploits a zero-day vulnerability in CrowdStrike Falcon Sensor to open a command prompt with SYSTEM privileges, the highest level of local operating privileges in Windows. According to the available information, the disclosed exploit works on the latest versions of Windows 11 and Windows Server, including Windows 11 25H2 and Windows Server 2025.

The vulnerability has not yet received a CVE number, and CrowdStrike has not confirmed its validity. The company told BleepingComputer that it is investigating the researcher’s claims and recommended that customers disable the Microsoft Office Windows policy setting that controls the File Suspicious Macro Removal feature within the protection platform.

What Does the Exploit Rely On?

FalconFlank is associated with CrowdStrike Falcon’s handling mechanism for malicious Office macros. Nightmare Eclipse said that the exploit enables privilege escalation even on a fully updated Windows system, noting that CrowdStrike may have added detections for it after its publication. The researcher also said that the proof of concept may require modifications, such as using exclusions or changing the DLL-loading method. These details were reported by the source as statements from the researcher and have not yet become a confirmed technical characterization by the company.

In contrast, CrowdStrike explained that customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. The company referred customers to a technical advisory available inside its support portal, but the advisory is not publicly published and can only be accessed with a CrowdStrike account. According to the source, the company did not respond to a subsequent inquiry about a public version of the advisory or whether a CVE number had been assigned to the flaw.

Why Does This News Matter?

The practical significance does not come solely from the existence of a published proof of concept, but from the nature of the exploitation point: it lies within security software running with elevated privileges, while its alleged successful exploitation leads to SYSTEM privileges on an updated device. This makes verifying the claim, identifying the affected versions, and determining whether current detections actually prevent exploitation central questions for defense teams.

Until a technical confirmation or official patch is issued, CrowdStrike’s announced action is to disable the suspicious macro removal policy while relying on the alternative cloud protection settings. This should be treated as temporary mitigation rather than evidence that the vulnerability has been closed, especially since the detailed advisory is not publicly available.

Broader Context for the Researcher’s Disclosures

The source reported that Nightmare Eclipse published zero-day exploits for Kaspersky Antivirus for Endpoint and GenDigital Avast Antivirus during the same week, under the names HardBreacher and PrettyPrague, in addition to the GreenSection exploit for disabling Nvidia systems. Cybersecurity expert Kevin Beaumont said that the privilege-escalation exploits published this week are real and work.

The researcher had also previously published exploits targeting Microsoft products since April, including Microsoft Defender, BitLocker, and other Windows components. Microsoft fixed some of those vulnerabilities, while other vulnerabilities remained without an official patch, according to the source. However, these developments alone do not prove the validity of FalconFlank, which remains a claim under investigation by CrowdStrike.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news