Researcher Publishes CrowdStrike Privilege Escalation Zero Day
ID: 70089954-b900-5a20-8b51-4664edf4deec
STIX ID: report--70089954-b900-5a20-8b51-4664edf4deec
Feed Name: Infosecurity Magazine (News)
A security researcher known as "Nightmare Eclipse" published a public proof-of-concept for FalconFlank, a zero-day privilege escalation that abuses CrowdStrike Falcon Sensor's Microsoft Office file malicious macro removal feature on up-to-date Windows systems; CrowdStrike has advised customers to disable that policy while investigating and has published a tech alert in its support portal, though no CVE has been assigned yet, and other researchers have validated the PoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
