Skip to main content
Emerging ThreatsMalware & Ransomware

CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems

Windows desktop computer on cluttered office desk with blank screen.

"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor," said the researcher known as Nightmare Eclipse, announcing a new exploit that — according to the researcher — can spawn a SYSTEM-level command prompt on fully patched Windows machines protected by CrowdStrike Falcon.

FalconFlank: what the exploit does

Nightmare Eclipse published a proof‑of‑concept called "FalconFlank" that the researcher says leverages CrowdStrike Falcon's Office malicious macros remediation feature to perform privilege escalation on affected hosts. The exploit, which has not been assigned a CVE identifier, is described by the researcher as enabling the attacker to spawn a command prompt with SYSTEM privileges on "a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon."

In the release notes the researcher warned that detections may already exist by the time the PoC is shared and advised anyone testing it to "add it to the exclusions or obfuscate the PoC and change the dll load technique."

Platforms named: Windows 11 25H2, Windows Server 2025, and CrowdStrike Falcon

The researcher explicitly named up‑to‑date Windows releases — Windows 11 25H2 and Windows Server 2025 — and tied the issue to CrowdStrike's endpoint platform. Successful exploitation, as described in the disclosure, depends on CrowdStrike Falcon's handling of Office files and its malicious macro remediation workflow.

Because the exploit targets the interaction between Microsoft Office macros and the Falcon sensor's remediation, the scope as reported covers both the operating system versions cited and customers running the referenced CrowdStrike feature.

CrowdStrike's response and customer guidance

A CrowdStrike spokesperson told BleepingComputer the company is "actively investigating these claims" and advised customers to disable the Microsoft Office "File Suspicious Macro Removal" Windows policy setting. The spokesperson added that "Customers remain protected through the Cloud Anti‑malware for Microsoft Office Files settings" and pointed customers to a FalconFlank technical alert available on CrowdStrike's support portal.

The published tech alert is not publicly accessible; CrowdStrike's advisory is available only to customers with accounts on its support portal, according to the reporting.

Other disclosures from Nightmare Eclipse and third‑party confirmations

Nightmare Eclipse has released several other exploit disclosures this week. The researcher published privilege‑escalation PoCs for Kaspersky Antivirus for Endpoint (named "HardBreacher") and GenDigital Avast Antivirus (named "PrettyPrague"), and a denial‑of‑service zero‑day for Nvidia (named "GreenSection") that the researcher said will crash the system.

Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released this week by Nightmare Eclipse "are real and work," according to the reporting.

Nightmare Eclipse has also disclosed multiple zero‑day exploits targeting Microsoft products since April, using names such as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. The report states that LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma have been fixed, while BlueHammer, RedSun, and UnDefend remain zero‑days awaiting a patch.

After the initial Microsoft disclosures, Microsoft responded with warnings of legal action against people engaging in "malicious activity causing real harm to our customers," language that the reporting says prompted many to interpret the company as directly threatening the researcher.

What this means for security teams, enterprise IT, and end users

  • Security teams: The immediate, reportable action CrowdStrike recommended is to disable the Microsoft Office "File Suspicious Macro Removal" Windows policy setting; teams will also need to review the FalconFlank Tech Alert in the CrowdStrike support portal if they have access. The researcher’s testing note — that detections may already exist and testers must add exclusions or obfuscate the PoC — underscores a risk that defensive telemetry may change once details circulate.
  • Enterprise IT and procurement leaders: The disclosure highlights an intersection between endpoint sensors and built‑in Office remediation behavior. Enterprises running the named Windows releases with CrowdStrike Falcon should track CrowdStrike's investigation and the availability of a public advisory or patched sensor update; the company’s message that "Customers remain protected through the Cloud Anti‑malware for Microsoft Office Files settings" will factor into mitigation choices.
  • End users and general public: The technical exploit targets remediation flows and privileged process elevation; the reporting does not identify widespread active exploitation beyond the published PoCs, but it does show multiple contemporaneous disclosures that defenders must reconcile.

Nightmare Eclipse's FalconFlank disclosure sits alongside a string of recent zero‑day releases and vendor responses; CrowdStrike is investigating and has issued targeted guidance that is currently accessible only to customers with portal access. Whether FalconFlank will receive a CVE assignment, when or how CrowdStrike will patch a sensor workflow if needed, and how rapidly enterprises will apply the advised policy change remain the next concrete developments to watch.

Original reporting: BleepingComputer — New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges