"We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting," a CrowdStrike spokesperson told The Register.
Who Nightmare Eclipse is and the recent streak of PoCs
The researcher self-identifying as Nightmare Eclipse — also using the names Chaotic Eclipse, Infinite Nightmare and MSNightmare — has broadened a recent campaign of published proof-of-concept (PoC) exploits beyond Microsoft products. According to the researcher’s GitHub README and related posts reported by The Register, those releases include FalconFlank (affecting CrowdStrike Falcon), HardBreacher (a Kaspersky elevation-of-privileges PoC), PrettyPrague (an elevation-of-privileges PoC targeting Gen Digital’s Avast), and GreenSection (an Nvidia memory-corruption issue that reportedly crashes systems).
What FalconFlank does and the conditions required
Nightmare Eclipse describes FalconFlank as a privilege-escalation vulnerability that abuses CrowdStrike Falcon’s Microsoft Office malicious macros remediation feature — an automated tool in the Falcon platform that inspects Office documents and strips suspect macro code. The PoC, the researcher says, works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with the platform set to Phase 3 - Optimal Protection and with the malicious macro removal feature enabled.
The researcher also warned that by the time of the public drop CrowdStrike likely had detections in place, and advised testers to add the PoC to exclusions or obfuscate the code and change the DLL load technique to avoid detection during validation.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCrowdStrike, Gen Digital, Kaspersky and Nvidia: vendor statements and silence
CrowdStrike confirmed it was investigating and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, while adding that "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings" and referring customers to a FalconFlank Tech Alert in the CrowdStrike support portal.
Gen Digital acknowledged a related vulnerability affecting a subset of its products, including Avast Antivirus, saying it "immediately initiated our security response procedures and are actively developing a patch" and that it takes the matter seriously. Kaspersky and Nvidia did not immediately respond to The Register’s requests for comment, according to the report.
Independent confirmation and community reaction
Security researcher Kevin Beaumont confirmed the FalconFlank exploit works, along with several other PoCs Nightmare released in the prior week. Beaumont told The Register he was not surprised to see Nightmare branching beyond Microsoft and said the pattern highlights "problems across the endpoint security space with the quality of the security products in terms of…security." Beaumont also said he hopes these disclosures will pressure vendors to prioritize hardened products over hyped threats.
Nightmare’s own commentary when publishing other PoCs was pointed: upon releasing HardBreacher the researcher wrote, "So the problem is now leaking outside of Microsoft," emphasizing that the recent series of disclosures targeted a range of endpoint and antivirus products.
How technologists, enterprises, and end users are likely to respond
- Technologists and security teams: Teams running CrowdStrike Falcon will need to evaluate CrowdStrike’s guidance — including disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting and reviewing the FalconFlank Tech Alert — and test configurations that include Phase 3 - Optimal Protection and the macro-removal feature enabled.
- Affected enterprises and procurement leaders: Organizations that deploy Kaspersky, Avast (Gen Digital) or CrowdStrike should track vendor advisories closely. Gen Digital stated it is developing a patch; Kaspersky and Nvidia were reported as not responding as of publication, which means procurement and incident response planners should monitor those vendors’ channels for updates.
- End users and the general public: The PoC disclosures underline that automated document-mitigation features are not immune to abuse when combined with product-specific behaviours; users should follow their organization’s security team guidance and avoid testing public PoCs on production systems unless explicitly sanctioned and isolated.
Nightmare Eclipse’s recent string of published PoCs — and the mixed vendor responses — underscores an uncomfortable reality reported by multiple sources in this incident: exploitable logic in endpoint products can be leveraged to elevate privileges, and public PoC drops accelerate pressure on defenders to examine configuration choices and vendor mitigations. CrowdStrike has issued a Tech Alert and a specific configuration recommendation; Gen Digital says a patch is in development; Kaspersky and Nvidia did not respond to requests for comment. The next concrete hinge in this story will be the patches and technical mitigations vendors publish — and whether those fixes change the conditions Nightmare identified.




