Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
A security researcher, Chaotic Eclipse, has released a proof-of-concept (PoC) called FalconFlank, a zero-day privilege escalation vulnerability affecting CrowdStrike Falcon. The exploit leverages a flaw in the office malicious macros remediation process, allowing an attacker to gain SYSTEM-level access on updated Windows 11 and Windows Server 2025 systems running CrowdStrike Falcon. The researcher has claimed that Microsoft is actively attempting to discredit them and prevent them from reporting vulnerabilities to vendors.
A security researcher, Chaotic Eclipse (also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse), has released a proof-of-concept (PoC) called FalconFlank, a zero-day privilege escalation vulnerability impacting CrowdStrike Falcon. The exploit targets a flaw in the office malicious macros remediation process within CrowdStrike Falcon. According to the researcher’s GitHub README, the PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon. The researcher has stated that Microsoft is actively attempting to discredit them and prevent them from reporting vulnerabilities to vendors, claiming the company is "trying hard to paint me as some insane criminal" and preventing them from reporting bugs.
"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher stated. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique." The PoC creates a file named `MY_SNAKE_IS_SOLID.dll` with full permissions for the current user in `C:\Windows\System32`.
This development follows Chaotic Eclipse's previous releases of PoCs for vulnerabilities impacting Kaspersky’s endpoint security product (HardBreacher) and Microsoft Defender (ShieldBreak). ShieldBreak, for example, allows an attacker to run arbitrary code with NT AUTHORITY\\
