Skip to main content
Emerging Threats

Security Researcher Exposes CrowdStrike Zero-Day Flaw

Security researcher pauses at desk with laptop and notebooks.

"FalconFlank is a zero-day privilege escalation that abuses the Office malicious macros remediation in CrowdStrike Falcon Sensor," wrote the researcher known as “Nightmare Eclipse” on GitHub on September 3.

FalconFlank: the exploit, the proof-of-concept and the environment

The researcher using the monikers Nightmare Eclipse (also published as Infinite Nightmare, MSNightmare) posted a public proof-of-concept (PoC) for an apparent zero-day privilege-escalation exploit named FalconFlank to GitHub on September 3. In their published note they stated the exploit "works in a fully updated Windows 11 25H2 / Windows Server 2025 with CrowdStrike Falcon – Phase 3 Optimal Protection + needs ‘Microsoft Office file malicious macro removal’."

Nightmare Eclipse also advised that, by the time of publication, CrowdStrike would likely have added detections and that anyone wishing to run the PoC would need to "add it to the exclusions or obfuscate the PoC and change the dll load technique." The post frames FalconFlank as targeting the Office malicious macros remediation capability within the CrowdStrike Falcon Sensor.

CrowdStrike guidance to customers and the support path

CrowdStrike responded with customer guidance instructing users to disable the "Microsoft Office File Suspicious Macro Removal" Windows policy setting while the company investigates. The vendor also said, "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings," and referred customers to a FalconFlank Tech Alert available in the CrowdStrike support portal.

Two operational details matter: the support portal referenced by CrowdStrike is accessible only to customers with dedicated accounts, and as of the publication of the PoC there had not been a Common Vulnerabilities and Exposures (CVE) identifier assigned to the issue.

Security community reactions and the researcher’s prior work

Independent security researcher Kevin Beaumont publicly confirmed that FalconFlank works and noted the same individual had published zero-days targeting other security vendors, specifically Kaspersky and Avast. Beaumont wrote on Mastadon that "An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity," and invoked a range of product failures—ranging from VPNs enabling ransomware entry to trivial EDR bypasses—to underline the broader concern.

Oliver Spence, CEO of CybaVerse, echoed a call for vendor responsibility: "How do we fix this? Vendors need to take greater responsibility for ensuring their products are secure, continually testing for weaknesses and remediating vulnerabilities quickly," he said, adding that without such steps "customers will continue to face the financial and operational penalties of these weaknesses."

Nightmare Eclipse is not new to public exploit dumps: the researcher was previously responsible for the "Exploitarium" release of more than 30 proof-of-concept exploits affecting open-source projects including the Linux kernel, Libssh2, FFmpeg, Gogs, and Gitea.

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams: The immediate, actionable item in CrowdStrike’s advisory is to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting and verify Cloud Anti-malware for Microsoft Office Files settings; teams with CrowdStrike accounts may also need to consult the FalconFlank Tech Alert in the vendor support portal for additional details.
  • Procurement leaders and affected enterprises: The comments from Oliver Spence and the public PoC publication underscore vendor-security scrutiny: procurement and vendor-risk teams will likely press for demonstrable secure-development practices, faster remediation timelines and clearer advisory access, given that the FalconFlank Tech Alert is gated behind customer support accounts.
  • Adversaries and testers: The PoC is public and the author explicitly advised how to run tests in an environment where detections may already be present—either by adding exclusions or obfuscating the PoC and changing DLL load techniques—steps that could be used by legitimate testers or repurposed by malicious actors.

The facts in hand are straightforward: a PoC for FalconFlank was posted to GitHub on September 3; CrowdStrike advised a specific policy change and referenced a customer-only tech alert; no CVE has been assigned; and prominent researchers have publicly validated the PoC while highlighting broader concerns about security-product vulnerabilities. The record now points to two concrete next items to watch inside vendor ecosystems: whether a CVE is assigned and whether CrowdStrike publishes further mitigation or a patch in its public advisories.

Original story: https://www.infosecurity-magazine.com/news/crowdstrike-privilege-escalation/