An anonymous researcher, known as Nightmare Eclipse, released a CrowdStrike Falcon zero‑day exploit called FalconFlank that lets attackers obtain SYSTEM privileges on up‑to‑date Windows 11 and Server 2025 systems. The vulnerability exploits CrowdStrike’s Office macro remediation feature and is currently unpatched, prompting the company to advise disabling a specific Office policy.

  • FalconFlank grants SYSTEM-level access on Windows 11/Server 2025
  • Disabling Microsoft Office’s ‘File Suspicious Macro Removal’ policy mitigates risk
  • Nightmare Eclipse released multiple zero‑days this week across various vendors

FalconFlank leverages a flaw in CrowdStrike Falcon Sensor’s Office macro remediation to spawn a command prompt with SYSTEM privileges. The attacker can do this on fully updated Windows 11 25H2 and Windows Server 2025 machines that run CrowdStrike.

In response, CrowdStrike is investigating the claim and has advised customers to disable the Windows policy setting that toggles the Office file suspicious macro removal feature. A technical alert is available on the CrowdStrike support portal, but it is not publicly accessible.

Earlier this week, Nightmare Eclipse also released privilege‑escalation zero‑days for Kaspersky (HardBreacher) and Avast (PrettyPrague), as well as a denial‑of‑service zero‑day for Nvidia (GreenSection).

Security expert Kevin Beaumont confirmed that these exploits are real and functional. Nightmare Eclipse has disclosed numerous Microsoft zero‑days since April, including LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend; some are patched, others remain unpatched.

Why This Matters

BozokMedia analysis shows that an attacker with SYSTEM privileges can control any application, enabling data theft, ransomware, or widespread system crashes. For CrowdStrike customers, this exposes a critical security gap in a widely used endpoint protection platform.

“As zero‑days proliferate, organizations must layer defenses and prioritize policy‑based controls.” – Dr. Anil Kumar, Cybersecurity Research Lead
Did You Know? Only 37% of cyber attacks are blocked after gaining valid credentials, underscoring the high risk of privilege escalation.

Frequently Asked Questions

Q1: Does FalconFlank affect all Windows versions?

A1: It is confirmed on Windows 11 25H2 and Windows Server 2025; other versions are still under testing.

Q2: Is there a patch available to mitigate this threat?

A2: CrowdStrike has not released a public patch; disabling the Office ‘File Suspicious Macro Removal’ policy is a temporary mitigation.