# FalconFlank Exploit Unveils Privilege Escalation Vulnerability in CrowdStrike Falcon

*Published September 4, 2026*
*Source: [https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html](https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html)*

## Executive Summary

Security researcher Chaotic Eclipse has released a new zero-day exploit, FalconFlank, which reveals a privilege escalation flaw in CrowdStrike Falcon Sensor. CrowdStrike is investigating the issue and has advised customers on interim protective measures.

## Article

Security researcher Chaotic Eclipse, known by several aliases including INFINITE NIGHTMARE, has introduced a new zero-day exploit called FalconFlank. This proof-of-concept (PoC) reveals a privilege escalation flaw within the CrowdStrike Falcon Sensor. According to the researcher, this flaw exploits the office malicious macros remediation feature in CrowdStrike Falcon. Although CrowdStrike may have existing detections for this vulnerability, the researcher advises that testing requires either excluding it from detection or obfuscating the PoC.

The proof-of-concept is effective on fully updated Windows 11 25H2 or Windows Server 2025 systems equipped with CrowdStrike Falcon. CrowdStrike has acknowledged the issue and is actively investigating the claims. They recommend customers disable the Microsoft Office File Suspicious Macro Removal policy while ensuring protection through the Cloud Anti-malware for Microsoft Office Files settings. Detailed guidance is available in the FalconFlank Tech Alert on the CrowdStrike support portal.

This development follows closely on the heels of Chaotic Eclipse's release of a PoC for another privilege escalation flaw affecting Kaspersky's endpoint security for Windows. This exploit, known as HardBreacher, has already been addressed by Kaspersky through an automatic update.

In addition to FalconFlank and HardBreacher, the researcher has also published a PoC for a Microsoft Defender zero-day named ShieldBreak, which remains unpatched. This exploit allows attackers to execute arbitrary code with elevated privileges, exploiting various elements of the Windows operating system. Despite these findings, the researcher has expressed frustration over a lack of communication from Microsoft regarding these vulnerabilities.
