A security researcher known as Nightmare Eclipse, who has previously focused on Microsoft vulnerabilities, has released proof-of-concept (PoC) exploit code for a new zero-day privilege escalation vulnerability affecting CrowdStrike's Falcon endpoint security platform. The vulnerability, dubbed "FalconFlank," was published on Thursday and reportedly abuses a feature within CrowdStrike Falcon designed to remediate malicious macros in Microsoft Office documents.
According to Nightmare Eclipse, FalconFlank exploits the automated security tool that inspects Microsoft Office documents and strips out suspicious macro code. The researcher claims the PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems, provided CrowdStrike Falcon is running with "Phase 3 - Optimal Protection" and the malicious macro removal feature is enabled.
CrowdStrike confirmed it is actively investigating the claims and has advised customers to disable the "Microsoft Office File Suspicious Macro Removal Windows policy setting." The company stated that customers remain protected through the "Cloud Anti-malware for Microsoft Office Files settings" and referred them to a "FalconFlank Tech Alert" in its support portal.
The researcher noted in a GitHub README that CrowdStrike would likely have detections for the exploit by the time of its release, suggesting that testers might need to add it to exclusions or obfuscate the PoC to bypass detection. An independent security researcher confirmed the exploit's functionality, along with several others recently released by Nightmare Eclipse.
This release marks a shift for Nightmare Eclipse, who has recently published vulnerabilities in other endpoint and antivirus products. Among these is "HardBreacher," an elevation of privileges bug affecting Kaspersky's endpoint antivirus product, specifically version 14.0.0.504 on a fully patched Windows 11 25H2 system. Kaspersky has not yet commented on this vulnerability.
Another zero-day, "PrettyPrague," targets Gen Digital's Avast antivirus software. This vulnerability is described as capable of dumping the SAM database by exploiting a flaw in Avast Sandbox and spawning a full SYSTEM shell. Gen Digital acknowledged the vulnerability affecting a subset of its products, including Avast Antivirus, and stated it is actively developing a patch.
Nightmare Eclipse also recently disclosed "GreenSection," an Nvidia memory corruption zero-day vulnerability. However, an independent analysis suggests this particular exploit primarily causes system crashes. Nvidia has not responded to inquiries regarding GreenSection.






