FalconFlank PoC Claims CrowdStrike Falcon Zero-Day Enables Privilege Escalation on Windows
Brief
A proof-of-concept (PoC) dubbed FalconFlank claims to exploit a previously undisclosed privilege-escalation issue in the CrowdStrike Falcon Sensor for Windows .
The alleged flaw is said to abuse Falcon’s remediation workflow for malicious Microsoft Office macros, potentially allowing a lower-privileged user to gain elevated access on fully patched Windows endpoints.
According to MSNightmare, FalconFlank affects devices running CrowdStrike Falcon with “Microsoft Office file malicious macro removal” enabled.
FalconFlank PoC Claims CrowdStrike Falcon Zero-Day
The researcher claims successful testing against fully updated Windows 11 25H2 and Windows Server 2025 systems configured with CrowdStrike Falcon’s Phase 3 Optimal Protection policy.
