Researcher publicly releases exploit for CrowdStrike Falcon privilege escalation

← Back to the feed

Researcher publicly releases exploit for CrowdStrike Falcon privilege escalation

The Register · 6 hours ago

Security researcher Nightmare Eclipse, previously known for a string of Microsoft zero-days, has published a proof-of-concept exploit for a new privilege escalation flaw in CrowdStrike's Falcon endpoint security platform, dubbed FalconFlank. The bug abuses Falcon's automated feature for stripping malicious macros from Microsoft Office documents, and works against fully updated Windows 11 25H2 and Windows Server 2025 machines running Falcon's Phase 3 optimal protection with the macro-removal feature enabled. It matters because it signals the researcher expanding their focus beyond Microsoft to the wider endpoint-security industry, raising questions about the robustness of tools that are themselves meant to defend against attacks.

CrowdStrike said it is investigating the claims and has advised customers to disable the "Microsoft Office File Suspicious Macro Removal" Windows policy setting while noting that its Cloud Anti-malware protections remain in place; researcher Kevin Beaumont confirmed the exploit works. FalconFlank follows a run of other disclosures from Nightmare Eclipse in recent days, including HardBreacher, a privilege escalation bug in Kaspersky's commercial endpoint antivirus, and PrettyPrague, an Avast flaw that can dump the Windows SAM database and spawn a SYSTEM shell. Gen Digital, which owns Avast, confirmed it is developing a patch; Kaspersky did not respond to requests for comment, and the researcher also released an Nvidia zero-day, GreenSection, which reportedly only crashes systems rather than escalating privileges.

  • Researcher publishes CrowdStrike Falcon privilege escalation exploit, FalconFlank.
  • CrowdStrike advises disabling a macro-removal policy setting as a workaround.
  • Researcher also hit Kaspersky, Avast and Nvidia products this week.

Software

Read the full article at the source →

Originally published by The Register as “Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC”.