ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

mediumExploit / PoCimportance 62
AI summary · glm-5.3-flash

Researcher NightmareEclipse published FalconFlank, a zero-day local privilege escalation in CrowdStrike Falcon Sensor abusing its Office malicious macro remediation feature.

A researcher known as Nightmare Eclipse published details of FalconFlank, a zero-day privilege escalation that abuses the Microsoft Office malicious macro removal feature in CrowdStrike Falcon Sensor, verified working on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection. CrowdStrike urged customers to disable the Office File Suspicious Macro Removal policy while it investigates, noting customers remain protected via Cloud Anti-malware for Microsoft Office Files; no CVE has been assigned. The same researcher previously released the Exploitarium dump of over 30 PoC exploits, and researcher Kevin Beaumont confirmed FalconFlank works.

  • FalconFlank abuses Falcon Sensor's Microsoft Office malicious macro removal for local privilege escalation
  • Works on fully patched Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection
  • CrowdStrike advises disabling the Suspicious Macro Removal policy; no CVE assigned yet
  • Same researcher previously published 30+ PoCs affecting Linux kernel, Libssh2, FFmpeg, Gogs, Gitea
Full article401 words · extracted from infosecurity-magazine.com · click to collapse

A security researcher has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike.

The individual, identified by their online moniker “Nightmare Eclipse” (aka Infinite Nightmare, MSNightmare) posted the details to GitHub on September 3.

“FalconFlank is a zero-day privilege escalation that abuses the Office malicious macros remediation in CrowdStrike Falcon Sensor. Obviously by the time I drop this CrowdStrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote.

“As of now it works in a fully updated Windows 11 25H2 / Windows Server 2025 with CrowdStrike Falcon – Phase 3 Optimal Protection + needs ‘Microsoft Office file malicious macro removal’.”

Read more about zero days in security products: Hackers Chain Two New SonicWall Zero-Day Vulnerabilities.

A statement from CrowdStrike urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the firm investigates the case.

"Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” it added. “We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal."

That portal is only accessible for customers with a dedicated account, and there has not yet been a CVE assigned to the bug.

The Nightmare Continues

Security researcher Kevin Beaumont confirmed that FalconFlank works, while also highlighting that the same researcher also published zero-days exploiting Kaspersky and Avast.

“An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity,” he wrote on Mastadon.

“From VPN products being one of the top causes of ransomware group entry, ../.. path traversal bugs, EDR products which brick PCs and are trivial to bypass and exploit etc.. It's a wild world out there.”

Oliver Spence, CEO of CybaVerse, agreed that security products can themselves be a risk to organizations.

“How do we fix this? Vendors need to take greater responsibility for ensuring their products are secure, continually testing for weaknesses and remediating vulnerabilities quickly,” he argued.

“Otherwise, customers will continue to face the financial and operational penalties of these weaknesses in the very products they depend on to secure them.”

NightmareEclipse was previously responsible for the “Exploitarium” dump of over 30 proof-of-concept exploits in open source projects, including the Linux kernel, Libssh2, FFmpeg, Gogs, and Gitea.

Infosecurity has reached out to CrowdStrike for additional comment.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/crowdstrike-privilege-escalation/