• News/
  • bleepingcomputer-20260904132201

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 4, 2026
·
Updated

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike's endpoint security platform. Successful exploitation allows attackers to spawn a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon's Office malicious macros remediation feature. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique," Nightmare Eclipse said. "As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon." When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company is investigating the researcher's claims and advised customers to disable the Microsoft Office Windows policy setting that toggles the security software's File Suspicious Macro Removal feature. "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows p...

Read full article

Affected Software

5 affected components
Microsoft Windows 11>=25H2<=25H2
Microsoft Windows Server>=2025<=2025
CrowdStrike Falcon sensor=up-to-date / latest versions
CrowdStrike Falcon endpoint security platform=latest versions
CrowdStrike Falcon sensor=works in fully updated Windows 11 25H2 / Windows Server 2025

Frequently Asked Questions

1

Which systems are reportedly affected by FalconFlank?

The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running the CrowdStrike Falcon sensor. The issue is described as affecting CrowdStrike Falcon's endpoint security platform and the latest versions of those Windows releases.

2

What access could successful exploitation provide?

Successful exploitation reportedly allows an attacker to spawn a command prompt with SYSTEM privileges. The exploit is said to abuse Falcon's Office malicious macros remediation feature.

3

Is this vulnerability confirmed and assigned a CVE?

The vulnerability has not yet been assigned a CVE ID. CrowdStrike said it is investigating after being asked for more details, while the exploit claims come from the anonymous researcher using the Nightmare Eclipse handle.

4

What does the researcher say is needed to test the proof of concept?

The researcher said CrowdStrike would likely already have detections for the exploit. They stated that testing may require adding it to exclusions or obfuscating the proof of concept and changing its DLL load technique.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203