BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 4, 2026 · 2 min read · Original story

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.

Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike's endpoint security platform.

Successful exploitation allows attackers to spawn a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon's Office malicious macros remediation feature.

"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique," Nightmare Eclipse said. "As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon."

When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company is investigating the researcher's claims and advised customers to disable the Microsoft Office Windows policy setting that toggles the security software's File Suspicious Macro Removal feature.

"We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting," the spokesperson told BleepingComputer. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal."

Although the company also shared this link to the tech alert regarding the FalconFlank zero-day exploit, the advisory is not public, and customers can access it only if they have an account on CrowdStrike's support portal.

CrowdStrike has yet to reply to a second email asking for a copy of the FalconFlank tech alert and whether a CVE ID has been assigned to the FalconFlank flaw.

Kaspersky, Avast, Nvidia, and Microsoft zero-days

This week, Nightmare Eclipse has also released privilege escalation zero-day exploits for Kaspersky Antivirus for Endpoint (named HardBreacher) and GenDigital Avast Antivirus (PrettyPrague), as well as a denial-of-service zero-day for Nvidia (named GreenSection) that will crash the system.

Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by Nightmare Eclipse this week are real and work.

Nightmare Eclipse has also disclosed multiple zero-day exploits targeting multiple Microsoft products since April, including Microsoft Defender, BitLocker, and various other Windows components.

These Microsoft zero-days are known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While the LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws have since been fixed, the other security flaws remain zero-days and are still awaiting an official patch.

After Nightmare Eclipse disclosed the first zero-days, Microsoft responded with warnings of legal action against people engaging in "malicious activity causing real harm to our customers," prompting many to believe that the company was directly threatening the security researcher.

References in this story

  1. Latest Nightmare Eclipse news www.bleepingcomputer.com The latest news about Nightmare Eclipse
  2. INFINITE NIGHTMARE (@MSNightmare2000) on X x.com FalconFlank : Crowdstrike Falcon 0day LPE is now public https://t.co/J0oBnyVkH5
  3. GitHub - MSNightmare/FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability github.com Crowdstrike Falcon 0day Privilege Escalation Vulnerability - MSNightmare/FalconFlank
  4. Login Template Title supportportal.crowdstrike.com
  5. GitHub - MSNightmare/HardBreacher: Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability github.com Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability - MSNightmare/HardBreacher
  6. GitHub - MSNightmare/PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability github.com GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability - MSNightmare/PrettyPrague
  7. GitHub - MSNightmare/GreenSection: Nvidia GreenSection Memory Corruption 0day vulnerability github.com Nvidia GreenSection Memory Corruption 0day vulnerability - MSNightmare/GreenSection
  8. Kevin Beaumont (@[email protected]) cyberplace.social Various different zero days in security products from Nightmare Eclipse. I’ve verified exploits real and work. Detections incoming. HardBreacher - Kaspersky Antivirus For Endpoint Elevation of Privileges Vulnerability…
  9. New Windows LegacyHive zero-day gives hackers admin privileges www.bleepingcomputer.com A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
  10. Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges www.bleepingcomputer.com A security researcher has released a new Microsoft Defender zero-day exploit named "RoguePlanet" just hours after Microsoft fixed two previously disclosed flaws during June 2026 Patch Tuesday.
  11. Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit www.bleepingcomputer.com Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions.
  12. New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges www.bleepingcomputer.com A researcher known as "Nightmare Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity…
  13. Windows BitLocker zero-day gives access to protected drives, PoC released www.bleepingcomputer.com A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
  14. Windows BitLocker zero-day gives access to protected drives, PoC released www.bleepingcomputer.com A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
  15. New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released www.bleepingcomputer.com A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems.
  16. A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure www.microsoft.com
  17. Microsoft Security Response Center (@msftsecresponse) on X x.com Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical…

Guides related to this story

← Back to all news