CrowdStrike Falcon zero-day exploit grants system privileges

On September 3–4, 2026, an anonymous security researcher using the alias Nightmare Eclipse released FalconFlank, a public proof-of-concept exploit for a zero-day vulnerability in CrowdStrike Falcon Sensor that allows local privilege escalation to SYSTEM level on Windows systems. The exploit abuses the endpoint protection software's Office malicious-macros remediation feature.

12 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Researcher releases CrowdStrike Falcon privilege escalation PoC

kite:cybersecurityother26d ago kagi ↗

A security researcher using the aliases Chaotic Eclipse, MSNightmare and Nightmare-Eclipse released FalconFlank, a public proof-of-concept project that the researcher says exploits a zero-day local privilege escalation flaw in CrowdStrike Falcon Sensor on Windows systems [cybersecuritynews.com#1][thehackernews.com#1]. The researcher says the technique abuses Falcon’s Office malicious macro remedia

Researcher releases CrowdStrike Falcon privilege-escalation zero-day PoC

kite:cybersecurityother26d ago kagi ↗

A security researcher using the aliases Chaotic Eclipse, Nightmare Eclipse, Infinite Nightmare and MSNightmare released FalconFlank, a proof-of-concept exploit for a claimed zero-day privilege-escalation flaw in CrowdStrike Falcon Sensor, on September 3, 2026 [thehackernews.com#1][theregister.com#1]. The researcher said FalconFlank abuses CrowdStrike Falcon’s Office malicious macros remediation fe

🤖 FalconFlank: 0-day local privilege escalation in CrowdStrike Falcon Sensor, abusing the Office malicious-macros remediation feature. Public PoC released by researcher with technical writeup. 🔗 htt

mastodon:infosec-exchangeother26d ago kagi ↗

🤖 FalconFlank: 0-day local privilege escalation in CrowdStrike Falcon Sensor, abusing the Office malicious-macros remediation feature. Public PoC released by researcher with technical writeup. 🔗 https:// thehackernews.com/2026/09/rese archer-releases-falconflank-poc.html # 0day # PrivEsc # CyberSec

Researcher Chaotic Eclipse published FalconFlank, a PoC for local privilege escalation in CrowdStrike Falcon Sensor. It abuses the remediation mechanism for malicious Office macros to escalate privile

mastodon:infosec-exchangeother26d ago kagi ↗

Researcher Chaotic Eclipse published FalconFlank, a PoC for local privilege escalation in CrowdStrike Falcon Sensor. It abuses the remediation mechanism for malicious Office macros to escalate privileges locally. This matters because a flaw in a trusted EDR can undermine endpoint security assumptions. # CrowdStrike # FalconFlank # PrivilegeEscalation https:// cyberworldops.eu/en/falconflan k-poc-r

🔹 The Hacker News Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nig

mastodon:infosec-exchangeother26d ago kagi ↗

🔹 The Hacker News Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious ma

Zero-Day Exploits Target CrowdStrike, Kaspersky, and Avast EDR Platforms Researcher Chaotic Eclipse released two more zero-day exploits (FalconFlank and PrettyPrague) that allow local privilege escala

mastodon:infosec-exchangeother25d ago kagi ↗

Zero-Day Exploits Target CrowdStrike, Kaspersky, and Avast EDR Platforms Researcher Chaotic Eclipse released two more zero-day exploits (FalconFlank and PrettyPrague) that allow local privilege escalation by abusing the remediation and sandbox features of CrowdStrike and Avast security software. **If you use CrowdStrike Falcon or Avast/Norton/AVG on Windows 11 or Windows Server 2025, watch closely

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Window

mastodon:infosec-exchangeother25d ago kagi ↗

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. https://www. bleepingcomputer.com/news/secu rity/new-crowdstrike-falconflank-zero-day-grants-system-privileges/

🤖 FalconFlank: 0day LPE abusing CrowdStrike Falcon Sensor's Office 'malicious macros remediation' feature. Works on fully patched Windows 11 25H2 / Server 2025. No CVE assigned yet — vendor investiga

mastodon:infosec-exchangeother25d ago kagi ↗

🤖 FalconFlank: 0day LPE abusing CrowdStrike Falcon Sensor's Office 'malicious macros remediation' feature. Works on fully patched Windows 11 25H2 / Server 2025. No CVE assigned yet — vendor investigating, advises disabling 'File Suspicious Macro Removal'. 🔗 https://www. bleepingcomputer.com/news/secu rity/new-crowdstrike-falconflank-zero-day-grants-system-privileges/ # 0day # EDR # CyberSec

🤖 FalconFlank: an anonymous researcher released a CrowdStrike Falcon zero-day exploit granting SYSTEM privileges on up-to-date Windows systems. Privilege escalation via the Falcon agent, PoC publishe

mastodon:infosec-exchangeother25d ago kagi ↗

🤖 FalconFlank: an anonymous researcher released a CrowdStrike Falcon zero-day exploit granting SYSTEM privileges on up-to-date Windows systems. Privilege escalation via the Falcon agent, PoC published. 🔗 https://www. bleepingcomputer.com/news/secu rity/new-crowdstrike-falconflank-zero-day-grants-system-privileges/ # 0day # Exploit # CyberSec