A security researcher has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike Falcon Sensor. The individual, known as Nightmаre Eclipse (also Infinite Nightmare, MSNightmare), posted the PoC to GitHub on 3 September. The researcher describes “FalconFlank” as a zero-day privilege escalation that abuses the Microsoft Office file malicious macro removal feature.
The write-up indicates the PoC functions in a fully updated Windows 11 25H2 / Windows Server 2025 environment with CrowdStrike Falcon – Phase 3 Optimal Protection – and notes a dependency on Microsoft Office file malicious macro removal being active. CrowdStrike has not yet assigned a CVE to this bug.
CrowdStrike has urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while it investigates. The firm emphasised that customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings and directed users to the FalconFlank Tech Alert in the CrowdStrike support portal. That portal is restricted to paying customers, and no public CVE has been disclosed at this time.
Observers including Kevin Beaumont have noted that FalconFlank has been used to publish zero-days for other vendors as well, while industry voices emphasise the broader need for vendors to strengthen secure-by-design practices. As with many such disclosures, the practical real-world impact hinges on deployment specifics, user configurations, and whether defenders can apply mitigations quickly.