AUTO-UPDATED

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

A security researcher known as Nightmare Eclipse has disclosed a zero-day privilege escalation exploit named FalconFlank affecting the CrowdStrike Falcon Sensor on fully updated Windows systems.

Key Points

  • The exploit, dubbed FalconFlank, targets the Microsoft Office malicious macro remediation feature within the CrowdStrike Falcon Sensor.
  • Security researcher Kevin Beaumont confirmed the vulnerability, which currently affects Windows 11 25H2 and Windows Server 2025.
  • CrowdStrike has advised customers to temporarily disable the Microsoft Office File Suspicious Macro Removal policy while an investigation is underway.
  • No CVE identifier has been assigned to the vulnerability, and technical details were published to GitHub on September 3.
  • The researcher, Nightmare Eclipse, has previously released proof-of-concept exploits for other major security products, including Kaspersky and Avast.

Why it Matters

This incident highlights the inherent risks posed when security software itself contains vulnerabilities that can be leveraged by attackers to gain elevated system access. It underscores the ongoing challenge for organizations to balance the deployment of protective tools with the potential for those same products to become new vectors for cyberattacks.
Infosecurity Magazine Published by Phil Muncaster
Read original