bleeping-computer · Crawled Sep 4, 2026

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

1 IoCs
Read original article ↗

AI Summary

An anonymous security researcher known as Nightmare Eclipse disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon, dubbed 'FalconFlank,' which allows attackers to achieve SYSTEM-level privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems. The exploit abuses the 'File Suspicious Macro Removal' feature in CrowdStrike Falcon Sensor by loading a malicious DLL. CrowdStrike has not yet assigned a CVE ID but advises customers to disable the related Microsoft Office policy setting while investigations continue. The researcher has also released other zero-day exploits targeting Kaspersky, Avast, Nvidia, and multiple Microsoft products.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename FalconFlank Details →