Zero-Day Flaw Found in CrowdStrike Falcon Sensor Allows Privilege Escalation
A security researcher known as 'Nightmare Eclipse' has publicly released details of a zero-day privilege escalation exploit affecting CrowdStrike Falcon Sensor. Named FalconFlank, the exploit abuses the way Falcon handles removal of malicious Office macros, and has been confirmed to work on fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon's Phase 3 Optimal Protection with the macro removal feature enabled.
CrowdStrike has responded by urging customers to disable the 'Microsoft Office File Suspicious Macro Removal' policy setting while it investigates, noting that its Cloud Anti-malware protections for Office files remain active in the meantime. Further guidance is available through a Tech Alert on the CrowdStrike support portal, though no CVE has yet been assigned. Independent researcher Kevin Beaumont has confirmed the exploit works, and noted the same researcher has previously published similar zero-days affecting Kaspersky and Avast products.
The incident has reignited debate about the security of the very tools businesses rely on for protection. CybaVerse CEO Oliver Spence argued that security vendors must take greater responsibility for testing and quickly fixing weaknesses in their own products, warning that customers otherwise bear the financial and operational cost of these flaws.