Tech News

FalconFlank Zero-Day in CrowdStrike Falcon Threatens Windows Systems

Researcher Nightmare Eclipse continues to give Microsoft and Windows a hard time, but this time through a security product: CrowdStrike Falcon. Here’s what we know about the FalconFlank exploit, which promises anyone using it the SYSTEM privileges on an up-to-date Windows machine.

Nightmare Eclipse, again. In early September, he published a new exploit code named FalconFlank. Its target: Falcon Sensor for Windows, in other words the agent installed on workstations and servers by CrowdStrike’s endpoint protection platform.

Need a quick refresher? If you read my articles regularly, you probably already know this researcher: Nightmare Eclipse. Since April 2026, he has been publishing zero-days on a regular basis, in retaliation against Microsoft after a dispute over how his reports were handled (with the MSRC). Notably, there was the RedSun flaw targeting Microsoft Defender, as well as YellowKey against BitLocker, from MiniPlasma, and then ShieldBreak, which bypassed Microsoft’s fix for the RoguePlanet flaw. This time, it is no longer Redmond’s company being directly targeted, but a security vendor: CrowdStrike.

FalconFlank: an exploit in a CrowdStrike product

FalconFlank is a local privilege escalation exploit, which means the attacker must already have access to the machine with a standard user account. A classic scenario, in short.

In the case of the FalconFlank exploit, the targeted mechanism is the malicious macro removal feature in Microsoft Office files. This is one of the remediation functions built into Falcon. It automatically inspects documents and removes code deemed dangerous, and for that it runs with elevated privileges (as is often the case with EDRs). These are the privileges the exploit hijacks to obtain a SYSTEM command prompt.

"FalconFlank is a 0day privilege escalation that abuses malicious Office macro remediation in CrowdStrike's Falcon Sensor", the researcher says in the README of his repository. According to him, the code works on fully up-to-date Windows 11 25H2 and Windows Server 2025 machines, with macro removal enabled. Of course, for this flaw to be exploitable, the Falcon Sensor solution must be installed on the machine.

For now, CrowdStrike has not made any official statement, but a recommendation has still been issued to those using this EDR: temporarily disable the feature that detects and removes malicious macros.

Kaspersky, Avast, and Nvidia targeted in the same wave

What is crazy about the FalconFlank exploit is that it did not come alone. In the same week, the researcher Nightmare Eclipse published two other privilege-escalation exploits and a third one more focused on denial of service:

  • HardBreacher against Kaspersky Antivirus for Endpoint
  • PrettyPrague against GenDigital’s Avast Antivirus
  • GreenSection, a denial-of-service attack targeting Nvidia.

The initial vendetta against Microsoft has therefore turned into a much broader campaign against the software vendor industry, especially those in cybersecurity. For now, nothing indicates that these flaws are already being exploited in the wild, but they are all valid. At least that is what researcher Kevin Beaumont says, whom I consider a reliable source.

More to come.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.