READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CrowdStrike Falcon Zero-Day Lets Local Attackers Grab SYSTEM Access on Fully Patched Windows Machines

CrowdStrike Falcon Zero-Day Lets Local Attackers Grab SYSTEM Access on Fully Patched Windows Machines
A researcher going by Chaotic Eclipse published working exploit code that turns CrowdStrike Falcon's own malicious-macro cleanup feature into a privilege escalation tool on fully updated Windows 11 and Windows Server 2025. CrowdStrike is investigating and told customers to disable a specific Office macro policy setting, but no patch or CVE exists yet. This is the same researcher's fourth security-vendor hit in about a week, following disclosures against Kaspersky and Avast, and it follows months of zero-days aimed at Microsoft Defender and other Windows components.

A security researcher who goes by Chaotic Eclipse, also using the handles INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, published a working proof-of-concept exploit on GitHub on September 3, 2026, targeting CrowdStrike Falcon. The exploit, named FalconFlank, abuses Falcon's feature for removing malicious macros from Microsoft Office files to escalate from a low-privileged local account to full SYSTEM access, according to Bleeping Computer and Security Affairs.

The researcher said the technique works on fully updated Windows 11 25H2 and Windows Server 2025 machines running Falcon with "Phase 3 Optimal Protection" and the macro-removal capability turned on, per the GitHub README cited by both The Hacker News and Security Affairs. No CVE identifier has been assigned as of this writing, according to Bleeping Computer.

A CrowdStrike spokesperson told Bleeping Computer, The Hacker News, and Cybersecurity News the same thing: the company is "actively investigating these claims" and advises customers to disable the "Microsoft Office File Suspicious Macro Removal" Windows policy setting. CrowdStrike says customers remain protected through separate Cloud Anti-malware settings for Office files, and pointed reporters to a FalconFlank tech alert on its support portal that is not publicly accessible.

There is no patch yet, and Bleeping Computer noted CrowdStrike did not respond to a follow-up email asking whether a CVE has been assigned.

The Independent Verification Question

Cybersecurity News flagged something important: the FalconFlank claim, as published, "has not been independently verified," and the researcher's own warnings that CrowdStrike detections and DLL-loading obfuscation may be needed to reproduce results "should be treated with caution." A GitHub repo with a README is not the same as a peer-reviewed disclosure.

Bleeping Computer reported that cybersecurity researcher Kevin Beaumont confirmed the privilege escalation exploits released this week by Nightmare Eclipse are real and functional. Beaumont is a well-known independent voice in the space.

Not Just CrowdStrike

This is part of a pattern, not an isolated bug. In the same week, the same researcher published HardBreacher, a privilege escalation flaw in Kaspersky Endpoint Security for Windows version 14.0.0.504. Kaspersky told The Hacker News it has resolved the issue through an automatic database update, though Security Affairs noted the PoC was described by the researcher as unstable and requiring repeated attempts to succeed.

The researcher also released PrettyPrague, targeting Avast Antivirus, which Tech Times reported can dump the Windows SAM database and spawn a full SYSTEM shell on patched Windows 11. Gen Digital, Avast's parent company which also owns AVG and Norton, confirmed the vulnerability to Tech Times and said it is developing a patch.

A fourth disclosure, GreenSection, is a denial-of-service flaw affecting Nvidia that crashes the system, according to Bleeping Computer.

Going back further, the same researcher has published Microsoft-focused zero-days since April, including flaws nicknamed LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and UnDefend, per Bleeping Computer. Last month's ShieldBreak disclosure, tracked as CVE-2026-69414 according to SOC Prime, targets Microsoft Defender and is assessed as a patch bypass for an earlier flaw, CVE-2026-50656 (RoguePlanet), according to The Hacker News. Microsoft has not released a fix for ShieldBreak.

Why the Same Trick Keeps Working

Every one of these bugs exploits the same structural fact: endpoint security software has to run with elevated privileges to do its job, and remediation workflows that touch the file system create a trust boundary an attacker can try to redirect. Security Affairs called this out directly, noting that "EDR products need elevated privileges to protect a system, but those same privileges can become an attack surface."

Tech Times reported that CrowdStrike's Falcon platform is deployed across more than 88,000 customer organizations, including 62 percent of the Fortune 500, based on the company's own disclosed figures. That scale is exactly why a working privilege escalation PoC against Falcon matters more than a similar bug against a smaller vendor. The blast radius, if the technique is weaponized before a patch lands, is enormous.

What Happens Next

CrowdStrike has not said when a permanent fix will ship or whether a CVE will be assigned. SOC Prime advised defenders to review Falcon exclusions, update detection logic for obfuscated DLL loading, and treat any unauthorized DLL writes to C:\Windows\System32 as a signal to isolate the host immediately.

Until CrowdStrike issues a patch, the company's own guidance stands: disable the Microsoft Office File Suspicious Macro Removal policy setting and rely on Cloud Anti-malware protections instead. Whether that mitigation fully closes the door, or just removes the specific path the public PoC uses, is the open question CrowdStrike has not yet answered on the record.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
Tech TimesCrowdStrike Falcon Zero-Day Turns Enterprise Security Agent Into Attack Surface - Tech Times
unknown
socprimeFalconFlank PoC Shows CrowdStrike Privilege Escalation
unknown
thedailycommit.inMSNightmare/FalconFlank
unknown
Bleeping ComputerNew CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
unknown
Cybersecurity NewsResearcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
unknown
Security AffairsChaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank
unknown
The Hacker NewsResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon