securityaffairs.com 9/3/2026, 10:35:35 AM · external

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank
CyberSIXT Evidence Panel
Primary Source github.com

CHAOTIC Eclipse has released a Proof of Concept (PoC) exploit named FalconFlank targeting a zero-day vulnerability in the Crowdstrike Falcon cybersecurity platform, specifically exploiting a privilege escalation flaw related to the Microsoft Office malicious macro removal feature. The exploit can elevate privileges from a low-privileged local user to a more powerful context on fully updated Windows 11 and Windows Server systems.

The researcher's announcement warns that while the PoC is available, CrowdStrike may already have countermeasures in place. This incident underscores a broader security concern regarding elevated privileges in Endpoint Detection and Response (EDR) products, which can be exploited by attackers with limited access.

The researcher is known for releasing various exploits for other anti-malware solutions including Kaspersky Endpoint Security and GenDigital's Avast Antivirus, drawing attention to the debate on responsible disclosure.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline