An anonymous security researcher who goes by the handle Nightmare Eclipse has released a zero-day exploit named FalconFlank that targets CrowdStrike Falcon, a widely used endpoint security platform. The exploit reportedly allows an attacker to escalate privileges and gain SYSTEM-level access on fully updated Windows systems. According to the researcher, the vulnerability affects the latest versions of Windows 11 and Windows Server when running CrowdStrike Falcon, and no CVE ID has been assigned yet.
The attack method abuses CrowdStrike Falcon’s Office malicious macros remediation feature, allowing the attacker to spawn a command prompt with SYSTEM privileges. Nightmare Eclipse stated that by the time the exploit was made public, CrowdStrike would likely have detections in place, meaning testing would require adding it to exclusions or obfuscating the proof-of-concept code. The researcher said FalconFlank works on a fully updated Windows 11 25H2 and Windows Server 2025 with CrowdStrike Falcon installed.
In response to inquiries from BleepingComputer, a CrowdStrike spokesperson said the company is actively investigating the claims. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, which is the feature tied to the exploit. The company added that customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings and pointed to a FalconFlank Tech Alert in its support portal, though that advisory is not public and requires a customer account to access.
CrowdStrike did not respond to a follow-up request for a copy of the tech alert or confirmation of whether a CVE identifier has been assigned to the flaw. The disclosure is part of a broader wave of zero-day releases from Nightmare Eclipse this week, which also included privilege escalation exploits targeting Kaspersky Antivirus for Endpoint and GenDigital Avast Antivirus, along with a denial-of-service zero-day for Nvidia that crashes the system. Cybersecurity expert Kevin Beaumont confirmed on Thursday that these privilege escalation exploits are real and functional.
Nightmare Eclipse has also been disclosing multiple zero-day exploits aimed at Microsoft products since April, with names such as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. Some of these, including LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, have since been patched by Microsoft. Other flaws, such as BlueHammer, RedSun, and UnDefend, remain unpatched and are still considered active zero-days.
Microsoft responded to the earlier disclosures with warnings of legal action against individuals engaging in malicious activity that causes real harm to its customers. That response led many observers to believe the company was directly threatening the security researcher. The situation highlights ongoing tensions between vulnerability researchers who publicly disclose flaws and vendors who prefer coordinated, private reporting. For US-based organizations using CrowdStrike Falcon, the immediate action advised by the vendor is to adjust the specific Windows policy setting while the investigation continues.
More cybersecurity news from TechManNews.







