Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 3, 2026, the researcher known as Nightmare Eclipse (aliases Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare) published FalconFlank on GitHub, a proof-of-concept exploit demonstrating a zero-day privilege escalation in CrowdStrike Falcon Sensor. The technique abuses the Microsoft Office malicious macro removal function built into the sensor, loading an attacker-controlled DLL with SYSTEM privileges on fully patched Windows systems.
- Zero-day exploit published September 3, 2026: abuses CrowdStrike Falcon Sensor's "Microsoft Office File Suspicious Macro Removal" feature.
- Confirmed working on fully patched Windows 11 25H2 and Windows Server 2025, per the researcher's direct statement reported by BleepingComputer.
- No CVE assigned and no patch available as of September 7, 2026; CrowdStrike has opened an investigation.
- Kevin Beaumont independently verified the exploit works, as reported by Infosecurity Magazine and BleepingComputer.
- The only officially documented mitigation is disabling the "Microsoft Office File Suspicious Macro Removal Windows" policy; CrowdStrike maintains customers remain protected via "Cloud Anti-malware for Microsoft Office Files" settings.
How the Exploit Works
The technical mechanism is documented in the researcher's GitHub README and reported by The Hacker News. FalconFlank "abuses the Office malicious macro removal in the CrowdStrike Falcon Sensor" to load an attacker-controlled DLL.
According to Rescana, the malicious DLL is "executed with SYSTEM privileges." BleepingComputer adds the exploit "allows attackers to achieve privilege escalation on updated Windows systems" and "spawn a SYSTEM command prompt." The attack requires prior code execution; it is not remotely exploitable.
The researcher anticipated CrowdStrike's reaction: "obviously when I release this CrowdStrike will already have detections, so if you want to test it you need to add it to exclusions or obfuscate the PoC and change the DLL loading technique." This statement, quoted directly by The Hacker News, indicates the researcher believes initial detections can be evaded.
Independent Confirmation and CrowdStrike Response
Kevin Beaumont independently verified the exploit works. Infosecurity Magazine and BleepingComputer agree on this confirmation. Beaumont's Mastodon quote — "most cybersecurity products are crap at cybersecurity" — is a general comment on security product quality, not a specific assessment of FalconFlank.
CrowdStrike's response, conveyed through spokespeople cited by three primary sources, comprises two elements. First: "We are actively investigating these claims." Second: "We advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting." In parallel, the company states "customers remain protected via the Cloud Anti-malware for Microsoft Office Files settings."
The FalconFlank Tech Alert, mentioned by Infosecurity and BleepingComputer, is hosted in the CrowdStrike support portal but not publicly accessible; its technical content is not verified by available sources.
Researcher Profile and Disclosure Context
Nightmare Eclipse operates under multiple aliases: Chaotic Eclipse, INFINITE NIGHTMARE, and MSNightmare. Techzine and The Hacker News confirm this multiplicity of identities. The researcher stated in an August 14, 2026 post, quoted by The Hacker News: "I can't even report bugs I find to the respective vendors due to Microsoft's restrictions, this is all their doing." This statement refers to a general situation, not specifically documented for FalconFlank.
Infosecurity Magazine reports the same researcher previously published an "Exploitarium" with over 30 proof-of-concepts for open source projects. Around the same time as FalconFlank, they disclosed zero-days for Kaspersky (HardBreacher), Avast (PrettyPrague), Nvidia (GreenSection), and Microsoft Defender (ShieldBreak/CVE-2026-69414), as documented by BleepingComputer, The Hacker News, and Techzine. This pattern contextualizes the researcher's experience but does not alter the specific nature of the FalconFlank vulnerability.
Recommended Actions
For organizations using CrowdStrike Falcon Sensor with the macro removal feature enabled, the actions documented in sources are:
- Evaluate disabling the "Microsoft Office File Suspicious Macro Removal Windows" policy, as directly recommended by CrowdStrike.
- Verify that "Cloud Anti-malware for Microsoft Office Files" settings are active, per CrowdStrike's statement on customer protection.
- Monitor the CrowdStrike support portal for potential publication of the FalconFlank Tech Alert or an advisory with CVE.
The decision to disable local macro removal depends on each environment's assessment of the coverage offered by cloud settings, an element not quantified in available sources.
Key StatNo CVE assigned as of September 7, 2026 — the vulnerability remains unclassified in the standard public scoring system despite confirmation of functionality on updated systems.
Source Limitations and Editorial Close
Information is based on the researcher's statements published on GitHub and convergent journalistic coverage from BleepingComputer, The Hacker News, Infosecurity Magazine, Techzine, and Rescana. No official CrowdStrike advisory with CVE or CVSS score exists. Journalistic sources repeat the same baseline information; no independent primary sources exist beyond the researcher's README.
It is unverified whether CrowdStrike's cloud anti-malware settings cover all potential attack vectors. No active exploitation in the wild is documented. FalconFlank's publication without vendor coordination and without a CVE identifier highlights a gap in the responsible disclosure process, with direct impacts on organizations' ability to track and prioritize the threat through standardized vulnerability management systems.
The situation remains fluid. The absence of a patch and CVE as of September 7, 2026 leaves defenses dependent on policy configurations that sources do not quantify in terms of comparative effectiveness. Kevin Beaumont's independent verification confirms the technical reality of the threat; CrowdStrike's response, pending investigative conclusion, offers only partial and non-definitive mitigations.
Information verified against cited sources and current as of publication.
Sources
- https://www.infosecurity-magazine.com/news/crowdstrike-privilege-escalation/
- https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/
- https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
- https://www.rescana.com/post/falconflank-zero-day-exposes-critical-privilege-escalation-vulnerability-in-crowdstrike-falcon-sensor-for-windows-11-and
- https://www.techzine.eu/news/security/144053/falconflank-exposes-crowdstrike-falcon-privilege-flaw/
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.