Researcher Chaotic Eclipse (aka Nightmare Eclipse) drops zero-day PoC wave: CrowdStrike FalconFlank, Microsoft Defender ShieldCrash, NVIDIA GreenSection, Avast PrettyPrague,…
Researcher Chaotic Eclipse — also publishing as Nightmare Eclipse/MSNightmare — released a series of working zero-day proof-of-concepts between September 3 and 9, 2026: FalconFlank (CrowdStrike Falcon local privilege escalation via Office macro removal),…
Researcher Chaotic Eclipse (identified by Security Affairs as the same person publishing as Nightmare Eclipse; GBHackers uses the name MSNightmare) published a rapid series of zero-day PoC exploits. FalconFlank abuses the Microsoft Office malicious macro removal remediation feature in CrowdStrike Falcon Sensor, which runs with high privileges, achieving local privilege escalation on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection and macro removal enabled; Kevin Beaumont independently confirmed it works. CrowdStrike says it is investigating, pointed customers to a FalconFlank tech alert, and advises disabling the Microsoft Office File Suspicious Macro Removal policy; customers remain protected by Cloud Anti-malware for Microsoft Office Files. No CVE has been assigned. ShieldCrash is a PoC showing the fix for the Malware Protection Engine privilege escalation CVE-2026-69414 (ShieldBreak) — which itself had bypassed the fix for RoguePlanet (CVE-2026-50656) — is incomplete: it performs arbitrary file reads as SYSTEM on supported Windows 10, 11 and Server systems running the September 2026 security updates and Malware Protection Engine version 1.1.26080.3, though The Register notes it does not yet enable writes or a full SYSTEM shell. It is the researcher's 11th Microsoft zero-day. Microsoft has not given a patch timeline; GBHackers reported no confirmed active exploitation and attributed a 'claims under review' statement to CrowdStrike, and no new CVE was assigned at disclosure. GreenSection exploits an out-of-bounds write in NVIDIA Windows user-mode components that share a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users; the unstable PoC crashes Vulkan or OpenGL applications and may allow cross-user access or compromise of dwm.exe; NVIDIA is actively investigating and no CVE or patch is mentioned. PrettyPrague, an Avast sandbox privilege escalation that dumps the SAM database for a SYSTEM shell and possibly affects other Gen Digital products including AVG and Norton, was initially reported as unpatched; The Hacker News reported Gen Digital patched it in versions 26.7.11086 and 26.8.11125, and SecurityWeek confirmed it was fixed. HardBreacher, a Kaspersky Endpoint elevation-of-privilege zero-day, was patched August 31. Beaumont confirmed the Avast and Kaspersky exploits also work. The researcher previously released the Exploitarium dump of…
- FalconFlank is a zero-day local privilege escalation in CrowdStrike Falcon Sensor abusing the Microsoft Office malicious macro removal remediation feature, which runs with high privileges; it works on fully updated Windows 11 25H2 and…
- CrowdStrike is investigating FalconFlank, published a FalconFlank tech alert, and advises disabling the Microsoft Office File Suspicious Macro Removal policy; customers stay protected by Cloud Anti-malware for Microsoft Office Files. No…
- Kevin Beaumont independently confirmed FalconFlank works; he also confirmed the Kaspersky (HardBreacher) and Avast (PrettyPrague) exploits, and SecurityWeek reports he confirmed the CrowdStrike exploit as well.
- ShieldCrash is a PoC showing the CVE-2026-69414 (ShieldBreak) patch is incomplete; ShieldBreak itself had bypassed the fix for RoguePlanet (CVE-2026-50656). It performs arbitrary file reads as SYSTEM on supported Windows 10, 11 and Server…
- ShieldCrash limitations per The Register: read-only (no arbitrary writes or full SYSTEM shell yet); it is the researcher's 11th Microsoft zero-day. Microsoft has not given a patch timeline. GBHackers reports no confirmed active…
- GreenSection is an out-of-bounds write in NVIDIA Windows user-mode components sharing a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users; the unstable PoC crashes…
- PrettyPrague is an Avast sandbox privilege escalation that dumps the SAM database for a SYSTEM shell, possibly affecting other Gen Digital products including AVG and Norton. Sources disagree on patch timing: The Register (Sept 3) said a…
- HardBreacher is a Kaspersky Endpoint elevation-of-privilege zero-day, patched August 31 per SecurityWeek.
Coverage timelineoldest first · each row is one article
- · 13d agoResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The Hacker News· 58
Researcher Chaotic Eclipse released FalconFlank, a zero-day privilege escalation PoC abusing CrowdStrike Falcon's Office macro remediation; CrowdStrike is investigating and issued a tech alert.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |