Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
Chaotic Eclipse disclosed FalconFlank, a zero-day privilege escalation flaw in CrowdStrike Falcon that abuses office malicious macros remediation in the Falcon Sensor and may already have detections. The researcher also recently published PoCs for HardBreacher in Kaspersky Endpoint Security and ShieldBreak in Microsoft Defender, both of which target Windows security products and can lead to SYSTEM-level impact. #FalconFlank #CrowdStrikeFalcon #HardBreacher #KasperskyEndpointSecurity #ShieldBreak #MicrosoftDefender

Keypoints

  • FalconFlank is a zero-day privilege escalation flaw in CrowdStrike Falcon Sensor.
  • The exploit abuses office malicious macros remediation in CrowdStrike Falcon.
  • The proof of concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems with CrowdStrike Falcon.
  • Chaotic Eclipse also released HardBreacher, a privilege escalation PoC for Kaspersky Endpoint Security for Windows.
  • The researcher previously published ShieldBreak, a Microsoft Defender zero-day tied to SYSTEM-level code execution.

Read More: https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html