Thursday, September 24, 2026

CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems

A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows.

CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing.

CrowdStrike Falcon Zero-Day

The project was published on GitHub on September 3 by a researcher using the MSNightmare account, also known as Chaotic Eclipse or Nightmare-Eclipse.

The project’s README describes FalconFlank as a zero-day vulnerability that affects Falcon’s ability to remediate malicious macros in Office documents.

The repository includes source materials and a compiled x64 release directory, prompting defenders to assess it as a potentially weaponizable local path.

According to the researcher, the proof of concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon with Phase 3 Optimal Protection, provided the Microsoft Office file malicious macro removal feature is enabled.

These claims have not yet been independently verified, and there is currently no public CVE or patch notice identifying the affected versions of Falcon Sensor.

The alleged issue involves privilege escalation, rather than initial remote access. An attacker would first need to execute code or have an account on the affected endpoint.

The claim is that a low-privilege local process can exploit a remediation workflow that operates with elevated rights, turning a protective function into a means of gaining a higher-privilege Windows security context.

If validated, this could allow an intruder with an established foothold to turn off defenses, access protected data, maintain persistence, or expand control over the environment.

CrowdStrike’s immediate advice is to turn off the affected Windows policy setting while keeping Cloud Anti-Malware protections for Microsoft Office files active. The company has also directed customers to a FalconFlank Tech Alert in its support portal.

Administrators should check the policy state across endpoint groups, verify that changes have been implemented, and maintain cloud-delivered anti-malware controls during this review.

Security teams should treat public exploit code as a significant event for detection and exposure management, even before a vulnerability receives a CVE designation.

They should review Falcon policy assignments, identify Windows systems using the macro removal capability, and monitor for unusual behavior related to Office document remediation, unexpected privilege changes, or anomalous child processes associated with the Falcon Sensor.

It is essential to preserve telemetry and investigate any signs of a standard user process obtaining administrative or SYSTEM-level execution.

Organizations should avoid implementing broad Falcon exclusions to test public exploit samples, as this can diminish available protection and decrease visibility.

Instead, they should validate compensating controls in an isolated lab, follow CrowdStrike’s authenticated support guidance, and stay alert for updated detections, a formal advisory, or sensor updates.

Until the investigation is complete, FalconFlank should be regarded as an alleged, publicly disclosed local privilege escalation issue, rather than a confirmed, fully scoped zero-day vulnerability in CrowdStrike.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication

A highly severe vulnerability in Roundcube Webmail is being...

Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks

Check Point has warned customers about the active exploitation...

New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network

AvisLoader, a newly observed Windows malware loader designed to...

Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks

An Integrated Security Operations Center (ISOC) in Microsoft Defender,...

RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials

A newly uncovered Android banking trojan dubbed RemControl is...

cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data

cPanel has released patches for CVE-2026-68490, a vulnerability related...

New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group

A newly identified ransomware operation tracked as Galago has...

Related Articles

Recent News