Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
A shared security 'Nightmare'
Prolific security researcher Nightmare Eclipse has released a proof-of-concept (PoC) exploit, FalconFlank, targeting CrowdStrike’s Falcon endpoint security platform. This vulnerability is a privilege escalation issue that exploits the Microsoft Office malicious macros remediation feature within CrowdStrike Falcon. The security tool scrutinizes Microsoft Office documents and removes potentially harmful macros, aiming to prevent malicious code from executing.
However, the FalconFlank exploit takes advantage of this process, allowing attackers to escalate their privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems with CrowdStrike Falcon Phase 3 – Optimal Protection and the malicious macro removal feature enabled. Additionally, Nightmare Eclipse has published exploits for other vulnerabilities, including HardBreacher in Kaspersky’s endpoint antivirus and PrettyPrague in Avast Antivirus.
Security experts, such as Kevin Beaumont, have confirmed the functionality of Nightmare’s exploits, urging cybersecurity vendors to improve their products' security and stop relying on hypothetical AI attacks.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.