An anonymous security researcher has released an alleged CrowdStrike Falcon zero-day exploit that can give attackers SYSTEM-level privileges on fully updated Windows computers.
The vulnerability, dubbed “FalconFlank” by the researcher known as Nightmare Eclipse, is claimed to affect Windows 11 and Windows Server systems running CrowdStrike’s endpoint security platform. It has not yet been assigned a CVE identification number.
According to the researcher, the exploit abuses Falcon’s feature for removing suspicious Microsoft Office macros. Successful exploitation could allow an attacker to open a command prompt with the highest level of Windows system access.
Nightmare Eclipse said the exploit worked against Windows 11 version 25H2 and Windows Server 2025 with the latest updates installed, alongside CrowdStrike Falcon. The researcher also claimed that CrowdStrike had likely introduced detections for the proof-of-concept, meaning it might need to be altered before testing.
CrowdStrike said it was investigating the claims and advised customers to disable the Microsoft Office Windows policy setting controlling its File Suspicious Macro Removal feature.
“Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” a company spokesperson said. CrowdStrike has issued a technical alert to customers through its support portal, although the advisory is not publicly accessible.
CrowdStrike Falcon zero-day under investigation
The disclosure comes after Nightmare Eclipse published several other alleged zero-day exploits this week, including privilege-escalation tools targeting Kaspersky Antivirus for Endpoint and Gen Digital’s Avast Antivirus. A separate exploit aimed at Nvidia products was described as capable of crashing a system.
Cybersecurity expert Kevin Beaumont said on Thursday that the privilege-escalation exploits released by the researcher this week were genuine and worked. His assessment did not remove the need for CrowdStrike to complete its investigation into FalconFlank.
Nightmare Eclipse has also disclosed alleged zero-days affecting Microsoft products since April, including Defender, BitLocker and other Windows components. Microsoft has fixed several of those vulnerabilities, while others remain without an official patch.
Following the earlier disclosures, Microsoft warned that it could take legal action against people involved in “malicious activity causing real harm to our customers”. The statement led to speculation that the company was addressing the researcher directly.
