A security researcher operating under the pseudonym Chaotic Eclipse has unveiled a new zero-day vulnerability called FalconFlank. This flaw, which permits privilege escalation, affects the CrowdStrike Falcon endpoint protection platform. The researcher, also known by aliases such as INFINITE NIGHTMARE and MSNightmare, detailed the exploit in a GitHub README file, noting that CrowdStrike may have already developed detection measures for this vulnerability.
Details of the FalconFlank Exploit
The FalconFlank exploit leverages malicious macros in Microsoft Office to bypass security measures within the CrowdStrike Falcon Sensor. According to Chaotic Eclipse, those wishing to test the proof of concept (PoC) must either exclude it from security checks or alter the DLL loading method to avoid detection. The researcher confirmed the PoC is functional on a fully updated Windows 11 25H2 machine and Windows Server 2025 running CrowdStrike Falcon.
While The Hacker News has reached out to CrowdStrike for their response, no official comment has been received at the time of writing. Updates will be provided as more information becomes available.
Previous Discoveries and Impact
This revelation follows another recent PoC release by Chaotic Eclipse, addressing a similar privilege escalation flaw in Kaspersky’s endpoint security for Windows. Dubbed HardBreacher, this exploit is described as makeshift but effective, allowing file creation with elevated permissions, potentially disrupting Kaspersky’s functionality.
Similarly, last month, Chaotic Eclipse disclosed a zero-day vulnerability in Microsoft Defender named ShieldBreak. This exploit could enable arbitrary code execution with high-level system privileges, impacting the security of Windows systems significantly. Despite the severity, Microsoft has not yet issued a fix, leading to criticism from the researcher.
Challenges in Vulnerability Reporting
Chaotic Eclipse has expressed frustration over the lack of communication from Microsoft, claiming that attempts to report vulnerabilities are often met with silence or dismissal. The researcher has indicated plans to disclose bugs to third-party vendors prior to the release of scheduled security updates, emphasizing a desire for normalcy and recognition for their work.
The ongoing tension highlights the complexities and challenges faced by independent security researchers in collaborating with major tech companies. As cybersecurity threats evolve, the importance of effective communication and timely patching remains critical to safeguarding systems worldwide.
In conclusion, the FalconFlank vulnerability underscores the need for vigilance and proactive measures in cybersecurity. Organizations relying on CrowdStrike Falcon and similar platforms should remain alert to updates and potential patches to mitigate risks associated with such exploits.
