Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/
ONE SENTENCE SUMMARY:
Researcher Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day enabling SYSTEM privilege escalation on updated Windows, prompting mitigations and broader scrutiny.
MAIN POINTS:
- Anonymous researcher “Nightmare Eclipse” published a CrowdStrike Falcon zero-day exploit named FalconFlank.
- Exploit reportedly works on fully updated Windows 11 25H2 and Windows Server 2025.
- Vulnerability currently lacks a CVE assignment and remains under investigation.
- Attack abuses Falcon Sensor’s Office malicious macros remediation to gain SYSTEM privileges.
- Successful exploitation spawns a SYSTEM command prompt via a proof-of-concept technique.
- Researcher expects detections, suggesting exclusions or PoC obfuscation to test.
- CrowdStrike advised disabling the Office policy enabling File Suspicious Macro Removal.
- CrowdStrike stated Cloud Anti-malware for Office Files continues to protect customers.
- FalconFlank technical alert exists but is restricted to CrowdStrike support portal accounts.
- Kevin Beaumont verified released privilege-escalation exploits from Nightmare Eclipse function as claimed.
TAKEAWAYS:
- EDR/AV features that remediate Office macros can become privilege-escalation attack surfaces.
- Immediate mitigation centers on disabling the specific Office policy tied to macro removal.
- Vendor guidance and detailed advisories may be gated, complicating rapid public understanding.
- Multiple concurrent zero-days from one source increase operational risk across security stacks.
- Technique-level evaluation matters because credentialed post-compromise stages reduce prevention effectiveness.