New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/

https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/

ONE SENTENCE SUMMARY:

Researcher Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day enabling SYSTEM privilege escalation on updated Windows, prompting mitigations and broader scrutiny.

MAIN POINTS:

  1. Anonymous researcher “Nightmare Eclipse” published a CrowdStrike Falcon zero-day exploit named FalconFlank.
  2. Exploit reportedly works on fully updated Windows 11 25H2 and Windows Server 2025.
  3. Vulnerability currently lacks a CVE assignment and remains under investigation.
  4. Attack abuses Falcon Sensor’s Office malicious macros remediation to gain SYSTEM privileges.
  5. Successful exploitation spawns a SYSTEM command prompt via a proof-of-concept technique.
  6. Researcher expects detections, suggesting exclusions or PoC obfuscation to test.
  7. CrowdStrike advised disabling the Office policy enabling File Suspicious Macro Removal.
  8. CrowdStrike stated Cloud Anti-malware for Office Files continues to protect customers.
  9. FalconFlank technical alert exists but is restricted to CrowdStrike support portal accounts.
  10. Kevin Beaumont verified released privilege-escalation exploits from Nightmare Eclipse function as claimed.

TAKEAWAYS:

  1. EDR/AV features that remediate Office macros can become privilege-escalation attack surfaces.
  2. Immediate mitigation centers on disabling the specific Office policy tied to macro removal.
  3. Vendor guidance and detailed advisories may be gated, complicating rapid public understanding.
  4. Multiple concurrent zero-days from one source increase operational risk across security stacks.
  5. Technique-level evaluation matters because credentialed post-compromise stages reduce prevention effectiveness.