CHAOTIC Eclipse has released a Proof of Concept (PoC) exploit named FalconFlank targeting a zero-day vulnerability in the Crowdstrike Falcon cybersecurity platform, specifically exploiting a privilege escalation flaw related to the Microsoft Office malicious macro removal feature. The exploit can elevate privileges from a low-privileged local user to a more powerful context on fully updated Windows 11 and Windows Server systems.
The researcher's announcement warns that while the PoC is available, CrowdStrike may already have countermeasures in place. This incident underscores a broader security concern regarding elevated privileges in Endpoint Detection and Response (EDR) products, which can be exploited by attackers with limited access.
The researcher is known for releasing various exploits for other anti-malware solutions including Kaspersky Endpoint Security and GenDigital's Avast Antivirus, drawing attention to the debate on responsible disclosure.