bleeping-computer · Crawled Sep 4, 2026
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
1 IoCs
Read original article ↗
AI Summary
An anonymous security researcher known as Nightmare Eclipse disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon, dubbed 'FalconFlank,' which allows attackers to achieve SYSTEM-level privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems. The exploit abuses the 'File Suspicious Macro Removal' feature in CrowdStrike Falcon Sensor by loading a malicious DLL. CrowdStrike has not yet assigned a CVE ID but advises customers to disable the related Microsoft Office policy setting while investigations continue. The researcher has also released other zero-day exploits targeting Kaspersky, Avast, Nvidia, and multiple Microsoft products.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | FalconFlank | Details → |