CrowdStrike Zero-Day Exploit Exposes Vulnerability in Popular Cybersecurity Product
A security researcher, known by their online moniker 'Nightmare Eclipse', has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike.
The exploit, dubbed 'FalconFlank', abuses the Office malicious macros remediation in CrowdStrike Falcon Sensor and works on fully updated Windows 11 and Windows Server 2025 systems with Phase 3 Optimal Protection enabled.
CrowdStrike has urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the firm investigates the case.
Security researcher Kevin Beaumont confirmed that FalconFlank works, highlighting the vulnerability in various cybersecurity products and suggesting that vendors need to take greater responsibility for ensuring their products are secure.