A newly disclosed FalconFlank zero-day reportedly allows attackers to gain SYSTEM-level privileges on fully updated Windows devices running the CrowdStrike Falcon sensor. CrowdStrike says it is investigating the claims and has issued mitigation guidance for customers.
FalconFlank exploit targets macro-remediation feature
An anonymous researcher known as Nightmare Eclipse released the proof-of-concept exploit on September 4.
The researcher claims the FalconFlank zero-day abuses CrowdStrike Falcon’s Microsoft Office malicious macro remediation capability. Successful exploitation can reportedly launch a command prompt with SYSTEM privileges.
The claimed flaw affects current versions of Windows 11, Windows Server and the CrowdStrike endpoint security platform. It has not yet received a CVE identifier.
Nightmare Eclipse said the exploit worked on fully updated Windows 11 25H2 and Windows Server 2025 systems with the Falcon sensor installed.
CrowdStrike issues temporary mitigation advice
CrowdStrike said it is actively investigating the researcher’s claims.
In the meantime, the company advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. This setting controls Falcon’s macro-remediation feature.
CrowdStrike said customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings. The company also directed customers to a FalconFlank technical alert in its support portal.
That advisory is not publicly available. Only CrowdStrike customers with support portal accounts can access it.
Researcher also disclosed other security zero-days
Nightmare Eclipse has released several other security flaws this week. These include privilege escalation exploits targeting Kaspersky Endpoint Security and Avast Antivirus.
The researcher also disclosed an Nvidia denial-of-service flaw that reportedly crashes affected systems. Cybersecurity expert Kevin Beaumont said the privilege escalation exploits published this week are genuine and work as described.
Since April, Nightmare Eclipse has also published zero-day exploits affecting Microsoft Defender, BitLocker and other Windows components. Microsoft has patched several of those flaws, while others remain without an official fix.
The FalconFlank zero-day highlights the need for organisations to review CrowdStrike’s mitigation guidance and monitor vendor updates while the investigation continues.


0 responses to “CrowdStrike FalconFlank zero-day reportedly grants SYSTEM privileges”