A new zero-day exploit called FalconFlank has been publicly released targeting CrowdStrike Falcon Sensor on Windows systems. The proof-of-concept was published on September 3, 2026, by a security researcher known as Chaotic Eclipse, also associated with the names MSNightmare and Nightmare-Eclipse. The exploit reportedly targets Falcon’s ability to detect and remove malicious macros from Microsoft Office files. If the technique works as demonstrated, a low-privileged user could potentially escalate privileges and reach the SYSTEM security level on an affected Windows machine.

FalconFlank is described as a local privilege-escalation attack rather than a method for gaining initial remote access to a computer. The attack takes advantage of the way Falcon handles suspicious Office documents during its remediation process. According to the published research, the exploit creates a specially prepared file and manipulates Windows file-system behavior so that a trusted process operating with higher privileges can be redirected toward an attacker-controlled file. This could potentially allow malicious code to be executed with much greater privileges than those available to the original user.

The publicly released project includes source code and a compiled Windows executable, making the disclosure more significant for security teams. Reports indicate that the researcher claims the technique works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon under specific protection settings. The exploit is connected to Falcon’s Microsoft Office suspicious macro removal capability, which normally identifies potentially dangerous macros and can remove them before the document is returned to the system. That remediation process is the key part being targeted by FalconFlank.

CrowdStrike has responded by saying that it is actively investigating the claims surrounding FalconFlank. The company has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the investigation continues. CrowdStrike also says customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings and has directed customers to the FalconFlank Tech Alert available through its support portal. At the time of these reports, there was no publicly announced CVE or confirmed vendor patch specifically identifying and fixing FalconFlank.

Security researchers have taken the disclosure seriously because the exploit code is already publicly available and the affected security software normally operates with powerful privileges on Windows endpoints. Vega reported that it reproduced the exploit in a controlled laboratory environment and developed detections for the activity. Researchers say defenders should pay attention to unusual DLL activity, suspicious file-system redirection, unexpected privilege changes and abnormal behavior involving Windows PowerShell directories or Falcon-related processes. However, the exact scope and affected Falcon versions still depend on the ongoing vendor investigation.

For organizations using CrowdStrike Falcon, the immediate priority is to review the affected policy setting and follow CrowdStrike’s official guidance while continuing to monitor endpoints for suspicious activity. Security teams should also avoid broadly disabling other Falcon protections or creating unnecessary exclusions simply to test the public exploit. FalconFlank should currently be described accurately as a publicly disclosed and reportedly working local privilege-escalation proof-of-concept, while CrowdStrike’s investigation is still underway. If the reported behavior is fully confirmed, the issue could become a serious concern because it would involve abusing an endpoint security product’s own privileged remediation process to obtain SYSTEM-level control.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news