Security Researcher Reveals Zero-Day Privilege Escalation Exploit in CrowdStrike
Recent reports indicate that a security researcher has disclosed a potentially significant zero-day privilege escalation exploit within CrowdStrike’s widely used cybersecurity platform. The researcher, known by the pseudonym “Nightmare Eclipse” (also referred to as Infinite Nightmare or MSNightmare), made this information public on GitHub on September 3.
The exploit, titled “FalconFlank,” reportedly exploits a specific functionality related to the remediation of malicious macros in the CrowdStrike Falcon Sensor. According to Nightmare Eclipse, the discovery suggests that by the time the details were released, CrowdStrike would likely have already developed detection mechanisms for the vulnerability. However, the researcher pointed out that users wishing to test the exploit would need to either modify their exclusion settings or obfuscate the proof of concept (PoC) to alter the DLL loading technique used in the exploit.
Nightmare Eclipse stated that FalconFlank is operable on fully updated Windows 11 25H2 and Windows Server 2025, in conjunction with the CrowdStrike Falcon Phase 3 Optimal Protection feature, and requires the "Microsoft Office file malicious macro removal" setting to be enabled. This combination makes the exploit feasible, raising alarms regarding the security of the systems it targets.
In light of the discovery, CrowdStrike has issued a statement advising its customers to disable the Microsoft Office File Suspicious Macro Removal policy while the company investigates this vulnerability further. The organization assured that clients continue to benefit from protection through its Cloud Anti-malware settings for Microsoft Office files. Moreover, they have directed customers to refer to the FalconFlank Tech Alert available in their dedicated support portal. Access to this portal, however, is restricted to customers with established accounts, and as of the announcement, a Common Vulnerabilities and Exposures (CVE) designation had not yet been assigned to the exploit.
The Ongoing Concerns From Researchers
Security researcher Kevin Beaumont has confirmed the exploit’s functionality. He also highlighted that Nightmare Eclipse is not new to the field of cybersecurity vulnerabilities; the same individual previously published zero-day exploits affecting Kaspersky and Avast’s security products. Beaumont shared insights on social media, emphasizing a pervasive acknowledgment among security researchers: many cybersecurity products are inadequate in their ability to provide effective security. He remarked on various vulnerabilities, including those stemming from VPN products and endpoint detection and response (EDR) solutions, which can inadvertently expose weaknesses in organizational defenses.
Commenting on the broader implications, Oliver Spence, CEO of CybaVerse, concurred with Beaumont’s assessment. Spence articulated the need for greater accountability among security vendors, stressing the importance of rigorous testing for vulnerabilities and prompt remediation of identified weaknesses. He suggested that the ongoing risk posed by security products could lead organizations to suffer significant financial and operational penalties if their dependencies do not operate as intended.
The actions of Nightmare Eclipse are particularly noteworthy given their previous initiatives, which include the “Exploitarium” release. This compilation featured over 30 proof-of-concept exploits targeting numerous open-source projects, including the Linux kernel, Libssh2, FFmpeg, Gogs, and Gitea. Such activities demonstrate a pattern of revealing vulnerabilities that not only put pressure on security products but also serve as a catalyst for improvements in cybersecurity practices across the industry.
As the cybersecurity landscape continues to evolve, the revelations regarding the FalconFlank exploit underscore the pressing need for both vigilance and innovation within the sector. Organizations reliant on security software must remain diligent, carefully considering the implications of vulnerabilities that could leave them open to exploitation.
Infosecurity Magazine has reached out to CrowdStrike for further comment, indicating that more information regarding their ongoing investigation may soon be released. As stakeholders monitor the situation, the ramifications of the FalconFlank disclosure could reshape approaches to cybersecurity, particularly regarding the development and deployment of anti-malware technologies.

