An anonymous researcher using the Nightmare Eclipse handle released FalconFlank, a CrowdStrike Falcon zero-day that can escalate privileges to SYSTEM on fully updated Windows 11 and Windows Server systems. CrowdStrike says it is investigating and advises customers to disable the Microsoft Office File Suspicious Macro Removal setting while it reviews the issue. #FalconFlank #NightmareEclipse #CrowdStrike #Windows11 #WindowsServer
Keypoints
- FalconFlank is a zero-day privilege escalation affecting CrowdStrike Falcon and modern Windows systems.
- Exploitation can spawn a command prompt with SYSTEM privileges.
- The flaw abuses Falconβs Office malicious macros remediation feature.
- CrowdStrike is investigating and recommends disabling the File Suspicious Macro Removal setting.
- Nightmare Eclipse also released other zero-days targeting Kaspersky, Avast, Nvidia, and Microsoft products.