Securityaffairs.Co
New Zero-Day Exploit FalconFlank Targets CrowdStrike Falcon Platform
Article Content
Chaotic Eclipse released FalconFlank, a proof-of-concept exploit for a zero-day privilege escalation vulnerability in the CrowdStrike Falcon cybersecurity platform. The exploit leverages the platform's 'Microsoft Office file malicious macro removal' feature to escalate privileges from a low-privileged user to a higher context. It is confirmed to work on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection. The researcher warns that CrowdStrike may already have detections for this exploit, indicating that while the vulnerability exists, it may be mitigated by the software. This release follows other exploits targeting Kaspersky and Microsoft Defender, showcasing a pattern of targeting major cybersecurity solutions. The researcher has previously noted issues with the stability of their exploits, indicating that repeated attempts may be necessary for successful execution.
Key Points: • FalconFlank exploits a privilege escalation flaw in CrowdStrike Falcon. • The exploit works on Windows 11 25H2 and Windows Server 2025 with specific configurations. • Chaotic Eclipse has a history of releasing exploits for multiple cybersecurity platforms.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.