logo

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

ID: 9fc37c14-cf4c-566c-8da8-74e77f2f17b2

STIX ID: report--9fc37c14-cf4c-566c-8da8-74e77f2f17b2

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-09-04

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

An anonymous researcher using the "Nightmare Eclipse" handle published a CrowdStrike Falcon zero-day named "FalconFlank" that enables local privilege escalation to SYSTEM by abusing CrowdStrike Falcon's Office malicious macros remediation on fully-patched Windows 11 and Windows Server systems; CrowdStrike is investigating and has advised disabling the Microsoft Office File Suspicious Macro Removal policy while providing a private tech alert. The report also notes multiple other zero-days the researcher released against Kaspersky, Avast, Nvidia, and various Microsoft components, some already patched and others still active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.