Rilasciato l'Exploit FalconFlank per CrowdStrike Falcon

FalconFlank Exploit Released for CrowdStrike Falcon

Security researcher known as Chaotic Eclipse has published a proof-of-concept (PoC) for a zero-day vulnerability dubbed 'FalconFlank' that affects the CrowdStrike Falcon security platform. The flaw exploits the Falcon sensor's malicious macro removal function in Microsoft Office files, which operates with elevated privileges, allowing a low-privileged local user to perform a privilege escalation on the system. The exploit was successfully tested on fully updated Windows 11 25H2 and Windows Server 2025 systems. Although CrowdStrike is implementing dedicated detections, the publication of the code significantly increases the risk for organizations that have not configured proper exclusions or obfuscation techniques.

Source: Security Affairs

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment