// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
Researcher Nightmare Eclipse released FalconFlank, a working zero-day privilege escalation PoC against CrowdStrike Falcon Sensor. The exploit abuses the sensor's malicious macro removal feature — a high-privilege component — to achieve SYSTEM-level execution. CrowdStrike confirms active investigation and advises a temporary mitigation, but no patch or CVE exists yet.

On September 3, 2026, the researcher known as Nightmare Eclipse — also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare — published FalconFlank on GitHub, a functional proof-of-concept for a local privilege escalation zero-day vulnerability in CrowdStrike Falcon Sensor. The PoC exploits the sensor's malicious Microsoft Office macro removal function, a high-privilege endpoint component, to gain SYSTEM-level execution. CrowdStrike has confirmed it is actively investigating and has provided a temporary mitigation, but has not released a patch or assigned a CVE.

Key Takeaways
  • FalconFlank is a zero-day PoC published September 3, 2026 that abuses the malicious macro removal function in CrowdStrike Falcon Sensor for local privilege escalation
  • The researcher states the PoC works on Windows 11 25H2 and Windows Server 2025 with CrowdStrike Falcon configured at Phase 3 Optimal Protection and macro removal enabled
  • CrowdStrike confirms the ongoing investigation and advises customers to disable the "Microsoft Office File Suspicious Macro Removal" policy; no CVE has been assigned
  • The same researcher has published zero-days for four endpoint security vendors in two months: Microsoft Defender, Kaspersky, Avast, and now CrowdStrike

How the Attack Works: Macro Removal as a SYSTEM Vector

The mechanics of FalconFlank revolve around an architectural contradiction. CrowdStrike Falcon Sensor operates with extremely elevated privileges to intercept, analyze, and neutralize threats in real time. Among its remediation functions, the sensor includes automatic removal of malicious macros in Microsoft Office files — an operation that requires deep system access to inspect documents, terminate processes, and modify content.

According to the researcher's GitHub README, FalconFlank "is a zero-day privilege escalation that abuses Office malicious macro remediation in CrowdStrike Falcon Sensor." The researcher adds a significant caveat: "obviously when I publish this CrowdStrike will already have detections, so if you want to test it you need to add it to exceptions or obfuscate the PoC and change the DLL loading technique." This note suggests the vendor's current detection focuses on the specific published vector, not necessarily on the underlying vulnerability class.

The researcher specifies the operational conditions: the PoC works "on fully patched Windows 11 25H2 / Windows Server 2025 with CrowdStrike Falcon – Phase 3 Optimal Protection" and requires the "Microsoft Office file malicious macro removal" policy to be active. The dossier does not reveal specific affected Falcon Sensor versions, nor full technical details on the DLL loading mechanism or the target SYSTEM process. SecurityOnline, while confirming the core claims, explicitly notes that sources keep these details "deliberately vague."

Source Convergence and Beaumont Verification

The PoC's functionality claim does not rest solely on the researcher's word. Kevin Beaumont, a well-known security expert, has independently verified that FalconFlank works. Infosecurity Magazine and SecurityWeek both cite this confirmation. Beaumont also contextualized the phenomenon in broader terms: "An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity," writing on Mastodon that "EDR products that brick PCs and are trivial to bypass and exploit" represent a systemic industry reality.

CrowdStrike's response was rapid but measured. A spokesperson stated: "We are actively investigating these claims and recommend customers disable the Windows Microsoft Office File Suspicious Macro Removal policy setting. Customers remain protected via the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." The Tech Alert, however, is accessible only to customer accounts — a choice that limits public verifiability of additional technical information.

The Nightmare Eclipse Pattern: Four Vendors in Two Months

FalconFlank is not an isolated incident. The researcher has published working zero-days for four major endpoint security vendors in the past two months. SecurityWeek places the CrowdStrike, Nvidia, and Avast releases in the same "early September 2026" window, while Infosecurity Magazine and Techzine trace a longer timeline: ShieldBreak against Microsoft Defender (with CVE-2026-69414, CVSS 7.8 HIGH), HardBreacher against Kaspersky, GreenSection against Nvidia, PrettyPrague against Avast, and now FalconFlank against CrowdStrike.

In September 2026 the researcher had already published the Exploitarium, a dump of more than thirty proof-of-concepts. The focus on endpoint security products is not accidental: these software require maximum system privileges to function, making them particularly lucrative targets for those seeking privilege escalation vulnerabilities. As Beaumont observes, "it's a wild world out there."

"An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity" — Kevin Beaumont, Mastodon

What to Do Now

For organizations using CrowdStrike Falcon, the documented actions are as follows:

  • Disable the "Microsoft Office File Suspicious Macro Removal Windows" policy as advised by CrowdStrike; cloud anti-malware protection for Microsoft Office files remains active
  • Verify that the Phase 3 Optimal Protection configuration aligns with the organization's security policies, given the PoC is tested specifically on this level
  • Consult the FalconFlank Tech Alert in the CrowdStrike support portal, if accessible with a customer account, for official technical updates
  • Monitor for formal CVE assignment and potential structural patch release, as no CVE has been assigned and no fix is currently available

The Architecture of Trust: When the Guardian Becomes the Gate

FalconFlank reveals a design problem that spans the entire EDR industry. The architecture of these products requires the sensor to operate with privileges higher than any other software, including the operating systems themselves in some isolation contexts. This structural position, functional to detection and response, simultaneously creates a concentrated, high-impact attack surface.

The sequence of Nightmare Eclipse zero-days suggests coordinated scrutiny of the EDR/AV industry, not opportunistic research. The researcher has demonstrated that different vendors share similar patterns: high-privilege remediation functions, inadequate scoping of system permissions, and gaps between detection of the specific exploit and understanding of the underlying vulnerability. For CISOs, the lesson is not only technical but architectural: reliance on a single endpoint product, however respected, introduces a privileged single point of failure that the organizational threat model must explicitly account for.

The dossier does not document exploitation in the wild nor attribution of the researcher's activity. No details emerge on the FalconFlank Tech Alert contents, CrowdStrike's patch roadmap, or potential detections for the vulnerability class beyond the specific PoC. What is documented is sufficient to outline a concrete risk for enterprises: a working, independently verified privilege escalation vector, with no available fix, in one of the world's most widely deployed EDR products.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. infosecurity-magazine.com
  2. securityweek.com
  3. thehackernews.com
  4. securityonline.info
  5. rescana.com
  6. techzine.eu
  7. securityaffairs.com