🚨Nightmare Eclipse Drops FalconFlank Zero-Day Bug Affecting CrowdStrike
CrowdStrike Falcon users, brace for a security headache
TL;DR
Security researcher Nightmare Eclipse has exposed a new zero-day vulnerability, FalconFlank, in CrowdStrike's Falcon platform. The bug allows privilege escalation via Microsoft Office macros, affecting fully updated Windows 11 and Windows Server systems. CrowdStrike advises disabling the macro removal feature.
Nightmare Eclipse has just dropped a new zero-day bug, FalconFlank, targeting CrowdStrike's Falcon endpoint security platform. This privilege escalation vulnerability exploits the Microsoft Office malicious macros remediation feature, hitting fully updated Windows 11 and Windows Server systems running CrowdStrike Falcon with Phase 3 - Optimal Protection and the malicious macro removal feature enabled. If you're using CrowdStrike Falcon, you need to act now: disable the macro removal feature to stay safe. The vulnerability can be exploited on systems running Windows 11 25H2 and Windows Server 2025, and a proof-of-concept exploit has been confirmed by security researcher Kevin Beaumont. CrowdStrike advises customers to disable the Microsoft Office File Suspicious Macro Removal policy setting, but the Cloud Anti-malware for Microsoft Office Files setting remains active for protection.

Key Points
FalconFlank is a privilege escalation vulnerability that abuses Microsoft Office's malicious macros remediation feature in CrowdStrike Falcon.
The PoC exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection.
Security researcher Kevin Beaumont has confirmed the PoC exploit works, adding to the list of recent vulnerabilities found by Nightmare.
Gen Digital's Avast antivirus software is also affected by PrettyPrague, a vulnerability that dumps the SAM database and spawns a full SYSTEM shell.
CrowdStrike advises customers to disable the Microsoft Office File Suspicious Macro Removal policy setting to mitigate the risk of FalconFlank.
Why It Matters
If you're using CrowdStrike Falcon with the Microsoft Office macro removal feature enabled, you're at risk. Disable this feature immediately to prevent privilege escalation. The vulnerability affects fully updated Windows 11 and Windows Server systems, and a confirmed PoC exploit is available. CrowdStrike's advice to disable the macro removal feature is crucial for security.
Frequently Asked Questions
Why does this matter?
If you're using CrowdStrike Falcon with the Microsoft Office macro removal feature enabled, you're at risk. Disable this feature immediately to prevent privilege escalation. The vulnerability affects fully updated Windows 11 and Windows Server systems, and a confirmed PoC exploit is available. CrowdStrike's advice to disable the macro removal feature is crucial for security.
What happened?
Security researcher Nightmare Eclipse has exposed a new zero-day vulnerability, FalconFlank, in CrowdStrike's Falcon platform. The bug allows privilege escalation via Microsoft Office macros, affecting fully updated Windows 11 and Windows Server systems. CrowdStrike advises disabling the macro removal feature.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,465 builders reading daily.