hacker-news · Crawled Sep 3, 2026

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

2 IoCs
Read original article ↗

AI Summary

Security researcher Chaotic Eclipse (aka INFINITE NIGHTMARE) disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon Sensor dubbed FalconFlank, which exploits the product's handling of malicious Office macros. A proof-of-concept (PoC) has been released and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed. The researcher also previously disclosed similar zero-days in Kaspersky's endpoint product (HardBreacher) and Microsoft Defender (ShieldBreak, CVE-2026-69414), the latter of which remains unpatched. The researcher claims Microsoft has not responded to their reports, prompting public disclosure.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename C:\Windows\System32\MY_SNAKE_IS_SOLID.dll Details →
Filename C:\Windows\System32\phoneinfo.dll Details →