Executive Summary
A critical zero-day vulnerability, designated FalconFlank, has been publicly disclosed in the CrowdStrike Falcon Sensor for Windows. This flaw enables local attackers to escalate privileges to SYSTEM on fully patched Windows 11 and Windows Server 2026 systems. The exploit leverages the Falcon Sensor’s Office malicious macros remediation feature, allowing adversaries to bypass endpoint security controls. The vulnerability was revealed by the security researcher known as Nightmare Eclipse (also known as Chaotic Eclipse), who released a working proof-of-concept (PoC) exploit. The public availability of this exploit code significantly increases the risk of opportunistic and targeted attacks. As of this writing, no official patch or CVE identifier has been issued, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
Technical Information
The FalconFlank vulnerability is a local privilege escalation (LPE) flaw affecting the latest versions of the CrowdStrike Falcon Sensor for Windows as of September 2026. The exploit abuses the Falcon Sensor’s Office malicious macros remediation feature, which is intended to protect endpoints from macro-based threats. By manipulating this remediation process, an attacker can load a malicious DLL that is executed with SYSTEM privileges, effectively granting the attacker full control over the affected endpoint.
The exploitation flow begins with the attacker leveraging the macro remediation feature to trigger the loading of a crafted DLL. This DLL is then executed in the context of the SYSTEM account, allowing the attacker to spawn a SYSTEM-level command prompt or execute arbitrary code with the highest privileges available on the system. The PoC author notes that CrowdStrike may have already deployed detection logic for this attack vector, so adversaries may attempt to obfuscate the PoC or modify the DLL loading technique to evade detection.
The vulnerability is confirmed to affect all supported versions of Windows 11 and Windows Server 2026 running the latest CrowdStrike Falcon Sensor as of September 2026. No explicit Falcon Sensor version numbers have been published in public advisories or technical write-ups. The exploit does not require remote code execution or network access; it is purely a local privilege escalation, meaning an attacker must already have code execution on the target system (for example, via phishing, malware, or another exploit).
Exploitation in the Wild
Security expert **** has independently confirmed that the exploit works as described by the original researcher. The public release of a working PoC on social media and code-sharing platforms has dramatically increased the risk of widespread exploitation. While there are currently no confirmed reports of active exploitation by advanced persistent threat (APT) groups or cybercriminal organizations, the criticality of the vulnerability and the availability of exploit code make it a high-value target for threat actors. The vulnerability is not yet assigned a CVE and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, so there is no CISA-confirmed exploitation at this time.
APT Groups using this vulnerability
As of this report, there is no public evidence that any APT groups or specific threat actors are exploiting FalconFlank in the wild. However, the public availability of a PoC and the critical nature of the vulnerability mean that it is likely to attract the attention of both financially motivated and state-sponsored actors in the near future. Organizations should remain vigilant and monitor for any signs of exploitation, as threat actors are known to rapidly weaponize newly disclosed privilege escalation vulnerabilities in widely deployed security products.
Affected Product Versions
The affected products are all versions of the CrowdStrike Falcon Sensor for Windows deployed on Windows 11 26H2 and Windows Server 2026, both fully updated as of September 2026. No explicit Falcon Sensor version numbers have been published in public advisories or technical write-ups as of this report. The vulnerability is confirmed to affect the latest available Falcon Sensor for Windows as of September 2026.
Workaround and Mitigation
CrowdStrike recommends that customers disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as a temporary mitigation. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. No official patch or CVE has been released as of this report. Organizations should also monitor for suspicious DLL writes in C:\Windows\System32, unexpected SYSTEM shell spawns from Falcon Sensor processes, and anomalous macro remediation events. SOC Prime has published detection logic for FalconFlank exploitation, including monitoring for pipe creation events linked to Falcon Sensor processes and file event monitoring for suspicious DLL writes in protected directories. If unauthorized DLL creation or SYSTEM shell spawning is detected, isolate the affected host and investigate for privilege escalation attempts originating from endpoint security processes.
Indicators of Compromise
Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
BleepingComputer: New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges, SOC Prime: FalconFlank Exposes CrowdStrike Falcon Privilege Escalation Risk, LinkedIn: Researcher Claims Zero-Day Privilege Escalation, Reddit: FalconFlank CrowdStrike Falcon 0day Privilege Escalation
Rescana is here for you
Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence to help you stay ahead of emerging threats. We are happy to answer any questions at info@rescana.com.



