CrowdStrike Falcon Sensor Flaw Allegedly Enables Local Privilege Escalation
Security researcher Nightmare-Eclipse (also known as Chaotic Eclipse and MSNightmare) has publicly released FalconFlank, a proof-of-concept (PoC) project claiming to exploit a local privilege escalation vulnerability in CrowdStrike’s Falcon Sensor. The flaw reportedly abuses the product’s remediation workflow for malicious Microsoft Office macros on Windows systems.
According to the project’s README, the issue affects devices with the "Microsoft Office file malicious macro removal" capability enabled. The researcher asserts the PoC successfully executed on fully updated Windows 11 (25H2) and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 Optimal Protection active. The repository includes C source code, Visual Studio project files, and a compiled x64 release.
The PoC allegedly grants attackers SYSTEM-level access by manipulating Falcon’s remediation processes, which typically operate with elevated permissions to quarantine or modify files. If validated, such a flaw could allow a local attacker with low-privilege access to escalate to administrative or SYSTEM rights, depending on system configuration.
At the time of reporting, CrowdStrike had not issued a public advisory, CVE identifier, or patch for the claimed vulnerability. The researcher notes that Falcon’s detections may already flag the PoC, and testing may require exclusions or payload adjustments though these claims remain unverified. The potential impact underscores the risks of privilege escalation in endpoint security agents, which require deep system access to function.
Security teams are advised to monitor CrowdStrike’s official communications for confirmation, mitigation guidance, or affected version details. Further technical validation and an official response are pending.
Source: https://cybersecuritynews.com/crowdstrike-falcon-0-day/
CrowdStrike TPRM report: https://www.rankiteo.com/company/crowdstrike
"id": "cro1788416624",
"linkid": "crowdstrike",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'CrowdStrike',
'type': 'Cybersecurity Company'}],
'attack_vector': 'Abuse of remediation workflow for malicious Microsoft '
'Office macros',
'description': 'Security researcher Nightmare-Eclipse has publicly released '
'FalconFlank, a proof-of-concept (PoC) project claiming to '
'exploit a local privilege escalation vulnerability in '
'CrowdStrike’s Falcon Sensor. The flaw reportedly abuses the '
'product’s remediation workflow for malicious Microsoft Office '
'macros on Windows systems.',
'impact': {'operational_impact': 'Potential SYSTEM-level access for local '
'attackers',
'systems_affected': 'Windows 11 (25H2), Windows Server 2025'},
'investigation_status': 'Pending validation and official response',
'recommendations': 'Security teams are advised to monitor CrowdStrike’s '
'official communications for confirmation, mitigation '
'guidance, or affected version details.',
'references': [{'source': 'FalconFlank PoC Repository'}],
'threat_actor': 'Nightmare-Eclipse (also known as Chaotic Eclipse and '
'MSNightmare)',
'title': 'CrowdStrike Falcon Sensor Flaw Allegedly Enables Local Privilege '
'Escalation',
'type': 'Local Privilege Escalation',
'vulnerability_exploited': "Falcon Sensor's remediation workflow for "
'Microsoft Office macros'}