New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
ID: 9fc37c14-cf4c-566c-8da8-74e77f2f17b2
STIX ID: report--9fc37c14-cf4c-566c-8da8-74e77f2f17b2
Feed Name: Bleeping Computer
An anonymous researcher using the "Nightmare Eclipse" handle published a CrowdStrike Falcon zero-day named "FalconFlank" that enables local privilege escalation to SYSTEM by abusing CrowdStrike Falcon's Office malicious macros remediation on fully-patched Windows 11 and Windows Server systems; CrowdStrike is investigating and has advised disabling the Microsoft Office File Suspicious Macro Removal policy while providing a private tech alert. The report also notes multiple other zero-days the researcher released against Kaspersky, Avast, Nvidia, and various Microsoft components, some already patched and others still active.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
