Anonymous Researcher Drops FalconFlank Zero-Day for CrowdStrike Falcon

A security researcher operating under the handle Nightmare Eclipse has publicly released a zero-day exploit dubbed FalconFlank that targets CrowdStrike Falcon's endpoint security platform. The exploit allows attackers to escalate privileges and spawn a command prompt with SYSTEM privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems. The vulnerability has yet to receive a CVE identifier.

The attack abuses Falcon's Office malicious macros remediation feature, specifically the File Suspicious Macro Removal capability. Nightmare Eclipse notes that CrowdStrike likely already ships detections for the released proof-of-concept, so testers would need to add exclusions or obfuscate the PoC to reproduce it. The researcher has also released zero-day exploits for Kaspersky and Avast endpoint products this week.

CrowdStrike says it is actively investigating the claims and advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as a precaution. The company states that customers remain protected through the Cloud Anti-malware for Microsoft Office Files setting and points customers to a FalconFlank Tech Alert in its support portal, though that advisory is only accessible to customers with a portal account.

Read More at the original source →