CrowdStrike Falcon Faces New Zero-Day PoC
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
The security researcher known as Nightmare Eclipse has turned their attention from a long-running campaign against Microsoft to a new target: CrowdStrike's Falcon endpoint platform. On Thursday, the researcher released a zero-day exploit called FalconFlank, which they say abuses a Windows-linked feature in Falcon to achieve privilege escalation.
A shift in focus
Nightmare Eclipse — a name used by a disgruntled security researcher who has also gone by Chaotic Eclipse, Infinite Nightmare, and MSNightmare — has spent months publishing zero-day vulnerabilities in Microsoft products. Now, according to their own posts, they are expanding their scope to other vendors in the endpoint security space.
The FalconFlank vulnerability targets the Microsoft Office malicious macros remediation feature built into CrowdStrike Falcon. That feature is designed to inspect Microsoft Office documents and strip out potentially harmful macros before they can execute when a user opens the file. Nightmare Eclipse claims the flaw allows an attacker to abuse this remediation process to elevate privileges on a fully patched system.
Proof-of-concept details
The proof-of-concept exploit works on systems running fully updated Windows 11 25H2 and Windows Server 2025, with CrowdStrike Falcon configured with Phase 3 - Optimal Protection and the malicious macro removal feature enabled, according to a GitHub README posted by Nightmare Eclipse.
In the README, the researcher acknowledged that CrowdStrike would likely have detections in place by the time the exploit was made public, writing: "Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique."
CrowdStrike's response
A CrowdStrike spokesperson told The Register: "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal."
Other exploits released
FalconFlank is not the only recent release from Nightmare Eclipse. Over the past week, the researcher has published several other vulnerabilities affecting endpoint and antivirus products from different vendors. These include HardBreacher, an elevation of privileges bug in Kaspersky's endpoint antivirus product, and PrettyPrague, a flaw in Gen Digital's Avast antivirus that the researcher says can "dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell."
Security researcher Kevin Beaumont confirmed that the FalconFlank exploit works, as do the HardBreacher and PrettyPrague proof-of-concept codes. Beaumont was not surprised by the shift to non-Microsoft targets, telling The Register: "Kinda makes sense they'd branch out to other vendors as there's problems across the endpoint security space with the quality of the security products in terms of…security unfortunately."
Vendor responses
Gen Digital, the parent company of Avast, acknowledged the PrettyPrague vulnerability in a statement to The Register: "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly."
Kaspersky did not immediately respond to requests for comment from The Register. Nightmare Eclipse also recently released an Nvidia memory corruption zero-day called GreenSection, but according to Beaumont, that one only crashes the system. Nvidia did not respond to inquiries.
Why this matters
The release of FalconFlank and the other exploits suggests that the endpoint security industry may face increased scrutiny from researchers who are willing to find and disclose flaws in widely used products. As Beaumont put it, the hope is that these disclosures will push vendors to "up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers." For organizations relying on these tools, this could mean a need to stay vigilant about patches and configuration guidance from vendors.
Sources
- The Register Original source
Continue Reading
PostgreSQL backup accounts open 12-year backdoor
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.
DMCA Ruling Tests Citizen Journalists' Rights
A federal court has ruled against citizen journalists in a DMCA takedown case, prompting the EFF to appeal.
CREST Launches AI Pentesting Accreditation
10 firms earn CREST's new AI-Enabled Penetration Testing accreditation, setting a governance standard.