New Zero-Day Vulnerability Discovered in CrowdStrike Falcon

A security researcher known as Nightmare Eclipse has released a proof-of-concept exploit for a zero-day vulnerability affecting CrowdStrike's Falcon endpoint security platform, raising concerns about its implications.

A new zero-day vulnerability, named FalconFlank, has been disclosed by the security researcher known as Nightmare Eclipse. This vulnerability impacts the CrowdStrike Falcon endpoint security platform and is linked to Microsoft Office’s malicious macros remediation feature.

Details of the Vulnerability

According to Nightmare Eclipse, FalconFlank is a privilege escalation vulnerability that exploits the automated security tool within CrowdStrike Falcon, which is designed to inspect Microsoft Office documents for potentially harmful macros. When harmful macros are detected, this feature is intended to strip the malicious code to prevent execution.

Current Status and Recommendations

CrowdStrike has acknowledged the claims and is currently investigating the situation. A spokesperson advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as a precaution. They emphasized that customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings and directed users to the FalconFlank Tech Alert available in the CrowdStrike support portal.

Proof-of-Concept Exploit

The proof-of-concept (PoC) exploit is confirmed to work on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with the malicious macro removal feature enabled. Nightmare Eclipse noted that users wishing to test the exploit would need to add it to exclusions or obfuscate the PoC to avoid detection.

Broader Implications

This release follows a series of vulnerabilities identified by Nightmare Eclipse in various endpoint security products, including a privilege escalation bug in Kaspersky’s endpoint antivirus and another zero-day in Gen Digital’s Avast antivirus software. Security researcher Kevin Beaumont confirmed the functionality of these exploits and remarked on the broader issues within the endpoint security landscape.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 378