FalconFlank Exploit Released for CrowdStrike Falcon
Security researcher known as Chaotic Eclipse has published a proof-of-concept (PoC) for a zero-day vulnerability dubbed 'FalconFlank' that affects the CrowdStrike Falcon security platform. The flaw exploits the Falcon sensor's malicious macro removal function in Microsoft Office files, which operates with elevated privileges, allowing a low-privileged local user to perform a privilege escalation on the system. The exploit was successfully tested on fully updated Windows 11 25H2 and Windows Server 2025 systems. Although CrowdStrike is implementing dedicated detections, the publication of the code significantly increases the risk for organizations that have not configured proper exclusions or obfuscation techniques.
Source: Security Affairs


Leave a Reply