Wednesday September 16, 2026

Advisory ID:   ngCERT-2026-090005

Damage:      Critical 

Probability:  High

Platform(s):  CrowdStrike Falcon Sensor for Windows

SUMMARY

ngCERT has identified FalconFlank, a project that claims to exploit a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor for Windows. The alleged flaw reportedly abuses the sensor’s Microsoft Office malicious macro remediation process and may allow a low-privileged local user to gain elevated privileges. Organisations using the affected functionality are advised to review their configurations and apply available mitigations.

DESCRIPTION

FalconFlank is a proof-of-concept released by security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, MSNightmare and INFINITE NIGHTMARE, which reportedly targets the Microsoft Office file malicious macro removal functionality of CrowdStrike Falcon Sensor for Windows. According to the researcher, the technique abuses the Falcon Sensor’s privileged remediation process for Office files containing malicious macros, potentially allowing a low-privileged local user to escalate privileges to a higher-privileged context. The researcher claims the PoC works on fully updated Windows 11 version 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 – Optimal Protection and the Microsoft Office file malicious macro removal feature enabled. CrowdStrike has stated that it is actively investigating the claims and has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, while noting that customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. The alleged vulnerability has not been independently verified, and no CVE identifier or CVSS score has been assigned at the time of this advisory.

CONSEQUENCES

Successful exploitation of the alleged vulnerability could allow an attacker to:

    1. Escalate from low-privileged user access to SYSTEM-level privileges.
    2. Execute unauthorised commands or applications with elevated privileges.
    3. Modify protected system files and resources.
    4. Bypass security restrictions applicable to standard user accounts.
    5. Establish persistence and conduct further malicious activities on affected endpoints. 

SOLUTION/MITIGATION

Organisations using CrowdStrike Falcon Sensor on Windows systems are advised to:

    1. Temporarily disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, where operationally feasible, in accordance with current CrowdStrike guidance.
    2. Maintain Cloud Anti-malware for Microsoft Office Files protection as recommended by CrowdStrike.
    3. Monitor official CrowdStrike security communications for further technical details, patches and confirmed remediation.
    4. Ensure CrowdStrike Falcon Sensor and Windows systems are maintained with the latest available updates.
    5. Monitor endpoints for unusual privilege-escalation activities, suspicious process execution and unexpected modifications to protected system locations.
    6. Review Falcon telemetry and endpoint security logs for indicators associated with the FalconFlank PoC.
    7. Apply the principle of least privilege and restrict unnecessary local administrative access.
    8. Conduct threat hunting on affected Windows endpoints, particularly systems where the Microsoft Office malicious macro removal functionality is enabled.  

HYPERLINK