Zero-day Privilege Escalation Reported in CrowdStrike
π‘οΈ A security researcher known as βNightmare Eclipseβ published a GitHub proof-of-concept on September 3 for a zero-day privilege escalation called FalconFlank that targets CrowdStrike Falcon Sensor. The exploit abuses the Microsoft Office file malicious macro remediation feature and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when specific CrowdStrike settings are enabled. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates and referenced a customer-only tech alert. No CVE has been assigned yet, and the researcher has also published other vendor zero-days previously.