News

CrowdStrike investigates Falcon privilege-escalation claim

A researcher released FalconFlank, a proof of concept that claims local privilege escalation in CrowdStrike Falcon through the Microsoft Office malicious-macro remediation workflow. CrowdStrike is investigating and told customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, saying Cloud Anti-malware for Microsoft Office Files remains the protective path. No public CVE or patch notice has been issued.

CrowdStrike investigates Falcon privilege-escalation claim

A researcher who publishes as Nightmare-Eclipse (also Chaotic Eclipse and MSNightmare) released FalconFlank, a proof of concept that claims a local privilege-escalation path in CrowdStrike Falcon. Cyber Security News updated its report on 4 September 2026 with a CrowdStrike spokesperson. The Hacker News also covered the release.

This is a researcher PoC plus a vendor investigation statement. It is not a confirmed CVE, not a remote code-execution bug, and not a CrowdStrike patch notice.

The claimed path sits in Falcon's remediation workflow for malicious Microsoft Office macros, and only when that policy is turned on. The researcher says the PoC worked on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection enabled.

CrowdStrike said it is "actively investigating these claims" and gave operators a concrete mitigation: disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers, the company said, "remain protected through the Cloud Anti-malware for Microsoft Office Files settings." It pointed customers to the FalconFlank Tech Alert in the CrowdStrike support portal.

That mitigation is the part most 0-day headlines skip. The named policy is the switch. Cloud Anti-malware for Microsoft Office Files is the path CrowdStrike says still covers the Office-file risk if you turn the policy off.

The privilege-escalation claim still needs validation. Public reporting has not assigned a CVE, and CrowdStrike has not published a patch. Treat FalconFlank as an unconfirmed local escalation claim against an endpoint agent that already runs with high OS privileges, the same class of trusted-tool risk as a JFrog Artifactory auth bypass or a WordPress migration-plugin takeover path.

It is a different shape from confirmed, in-the-wild appliance bugs such as SonicWall's SMA 1000 zero-days or the Cisco Nexus 9000 Silicon One root RCE. Those had vendor CVEs and fixes. This one, so far, has a PoC and a support-portal alert.

A Falcon admin should check that named policy today, open the FalconFlank Tech Alert in the support portal, and watch for a CVE or patch before treating the claim as closed.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free