time 2 minute read

CrowdStrike Investigating "FalconFlank" Privilege Escalation Claim

A security researcher using the name "Nightmare Eclipse" has disclosed a reported zero-day privilege escalation vulnerability in CrowdStrike Falcon Sensor known as "FalconFlank". At the time of writing, no CVE has been assigned to the issue.

Based on the information published so far, the reported issue affects fully patched Windows 11 and Windows Server systems running CrowdStrike Falcon. The exploit is said to abuse Falcon’s malicious macro remediation capability in Microsoft Office. If confirmed, the technique could allow an attacker to elevate privileges and open a SYSTEM-level command prompt, giving them full control of the affected machine.

The researcher also stated that CrowdStrike is likely to deploy detection signatures now that details of the exploit are public. That means future testing of the proof-of-concept may require modification or allow-listing to avoid detection. The exploit author further claims the technique works against fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon.

CrowdStrike has acknowledged the report and is actively investigating. In guidance first published on September 3, the vendor advised customers to disable the Microsoft Office File Malicious Macro Removal policy setting in Falcon’s Next-Gen Antivirus settings under Clean Infected Microsoft Office Files. According to CrowdStrike, turning off that setting stops malicious macros from being automatically replaced. The company also said organizations aligned to CrowdStrike best practices should continue to receive protection through Cloud Anti-malware for Microsoft Office Files, which remains active.

On September 4, CrowdStrike issued a further update stating that it had globally deployed multiple behavioral protections to help detect and prevent potential exploitation across several stages of the attack chain. The vendor also said it will continue to monitor the threat landscape and strengthen protections as new information becomes available.

CrowdStrike’s Counter Adversary Operations and OverWatch teams are also actively hunting for signs of attempted exploitation. CrowdStrike has stated that the affected feature is not available in US-GOV-1 or US-GOV-2 environments, and customers operating in those government cloud environments are not impacted.

Our CrowdStrike access indicates the vendor is continuing to update its advisory as more information becomes available. CrowdStrike has published FalconFlank guidance in its support portal, but that advisory is restricted to customers with portal access and is not publicly available. If your team uses CrowdStrike, log in to the Falcon portal and search "FalconFlank" to review the latest vendor guidance and recommendations.

It remains unclear whether a CVE will ultimately be assigned, and CrowdStrike’s investigation is ongoing. Helient will continue monitoring developments and sharing updates as more information becomes available.

If you need help reviewing your CrowdStrike policies or putting the recommended mitigation in place, contact us at service@helient.com.