Researcher Publishes FalconFlank PoC for CrowdStrike
🔒 A security researcher known as Chaotic Eclipse released a zero-day PoC called FalconFlank that enables local privilege escalation by abusing CrowdStrike Falcon's office malicious macros remediation. The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed, and cautions defenders may need to add exclusions or obfuscate detection to test it. This release follows recent PoCs targeting Kaspersky and Microsoft Defender, with the researcher criticizing vendor engagement.
