Zero‑Day Privilege‑Escalation in CrowdStrike Falcon (FalconFlank) Grants SYSTEM Access on Windows 11/Server
What Happened — An anonymous researcher (Nightmare Eclipse) disclosed a zero‑day flaw in CrowdStrike’s Falcon endpoint sensor that lets an attacker spawn a command prompt with SYSTEM privileges on fully patched Windows 11 25H2 and Windows Server 2025. The exploit abuses the “Office malicious macros remediation” feature of the Falcon sensor; no CVE has been assigned yet.
Why It Matters for Trust & Control Assurance
- Demonstrates how a privileged‑escalation gap can bypass even up‑to‑date endpoint controls, a scenario continuous control‑assurance programs are built to detect and evidence.
- Highlights the need for real‑time monitoring of privileged‑execution events and the ability to produce audit‑ready logs showing that critical controls (e.g., least‑privilege enforcement) are operating as intended.
- Aligns with the Access Control control objective: enforce least‑privilege and prevent unauthorized elevation of privileges.
Who Is Affected – Enterprise IT environments using Windows 11/Server with CrowdStrike Falcon deployed; security teams of technology vendors and managed‑service providers.
Recommended Actions
- Immediately disable the “Microsoft Office File Suspicious Macro Removal” policy setting in CrowdStrike Falcon as advised by the vendor.
- Deploy any interim patches or mitigations released by CrowdStrike; monitor the support portal for the forthcoming tech alert.
- Augment endpoint detection rules to flag unexpected SYSTEM‑level command‑prompt launches and log them for audit.
- Conduct a rapid control‑validation exercise on privileged‑execution controls and document findings for compliance readiness.
Technical Notes – The exploit leverages the Falcon sensor’s macro‑remediation component to load a malicious DLL, granting SYSTEM rights. No CVE ID assigned yet; the vulnerability is present in the latest Falcon sensor versions on Windows 11 25H2 and Windows Server 2025. Source: BleepingComputer