A security researcher known as Nightmare Eclipse has disclosed a zero-day privilege escalation exploit named FalconFlank affecting the CrowdStrike Falcon Sensor on fully updated Windows systems.
Key Points
- The exploit, dubbed FalconFlank, targets the Microsoft Office malicious macro remediation feature within the CrowdStrike Falcon Sensor.
- Security researcher Kevin Beaumont confirmed the vulnerability, which currently affects Windows 11 25H2 and Windows Server 2025.
- CrowdStrike has advised customers to temporarily disable the Microsoft Office File Suspicious Macro Removal policy while an investigation is underway.
- No CVE identifier has been assigned to the vulnerability, and technical details were published to GitHub on September 3.
- The researcher, Nightmare Eclipse, has previously released proof-of-concept exploits for other major security products, including Kaspersky and Avast.