FalconFlank demo lifts CrowdStrike Falcon privileges on patched Windows

A new public exploit abuses CrowdStrike Falcon Sensor's macro cleanup routine to raise privileges on fully patched Windows.

CSBadmin
1 Min Read

Chaotic Eclipse has dropped FalconFlank, proof-of-concept code that escalates privileges on machines protected by CrowdStrike Falcon Sensor. The researcher’s writeup says the zero-day abuses the sensor’s automated cleanup routine for malicious Office macros, and that it runs on a fully updated Windows 11 25H2 system or on Windows Server 2025.

The README adds that CrowdStrike may already detect the flaw, and that anyone testing the code may need to add it to exclusions or obfuscate the PoC and change the DLL load technique for it to run.

FalconFlank carries no CVE identifier and no vendor advisory as of publication. It continues a run of public bypass disclosures from the same account, whose author has said vendors stop engaging once bugs are reported, leaving public release as the only outlet.

Organizations running CrowdStrike Falcon should watch for vendor guidance, review exclusion lists, and treat the disclosure as a cue to verify that macro remediation telemetry still fires in their environment. Exploit code in the open raises the odds that the bug gets folded into real intrusions before a fix lands.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.