A researcher known as Chaotic Eclipse has published FalconFlank, a proof-of-concept for a zero-day privilege escalation flaw in CrowdStrike Falcon Sensor. CrowdStrike says it is investigating and advises customers to disable a specific macro removal policy setting in the meantime.
The exploit abuses the Office malicious macro remediation feature in the Falcon Sensor, according to a GitHub README published by the researcher on Wednesday. It runs on a fully updated Windows 11 25H2 machine or Windows Server 2025 with Falcon installed. The researcher notes that CrowdStrike may already detect the technique, meaning testers would need exclusions or an obfuscated variant.
CrowdStrike confirmed to The Hacker News that it is looking into the report. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a spokesperson said. Customers stay protected through the Cloud Anti-malware for Microsoft Office Files settings, the company added, pointing to a FalconFlank Tech Alert in its support portal.
Third vendor in weeks
A few days before FalconFlank, the same researcher dropped HardBreacher, a privilege escalation PoC for Kaspersky’s Windows endpoint product version 14.0.0.504. Kaspersky told The Hacker News the issue has been fixed and that the update arrives automatically or via a manual database refresh.
Before that came ShieldBreak, tracked as CVE-2026-69414, a Microsoft Defender zero-day allowing arbitrary code execution with SYSTEM privileges. It is a bypass of an earlier fix for CVE-2026-50656, also known as RoguePlanet. Microsoft has acknowledged the CVE and says an update is in development, but no patch has shipped. Public testing suggests the exploit only works when Defender is the active antivirus.
An ongoing standoff with Microsoft
The same alias has been tied to BlueHammer, RedSun and LegacyHive. In a post dated 14 August, the researcher said Microsoft refuses “any sort of communication” and claimed restrictions prevent them from reporting bugs to other vendors. Microsoft has since stated it has no intention to pursue action against individuals conducting or publishing security research, while reserving the right to act against illegal activity.
Also read: CrowdStrike pits offensive and defensive AI against each other