Researcher publishes 'FalconFlank' zero-day exploiting CrowdStrike Falcon on Windows 11/Server 2025
A researcher going by 'Nightmare Eclipse' released a privilege-escalation exploit dubbed FalconFlank that abuses CrowdStrike Falcon's malicious macro remediation feature to gain SYSTEM-level command prompt access on fully patched Windows 11 25H2 and Windows Server 2025 machines. The flaw has no CVE yet, and CrowdStrike says it is investigating while telling customers to disable the Office File Suspicious Macro Removal policy setting as a workaround.