Cyber & Resilience - 6 min read - 5 September 2026

CrowdStrike hasn't confirmed a CVE, an advisory or a patch. The proof-of-concept is already public.

FalconFlank is a claimed privilege-escalation technique that allegedly turns CrowdStrike Falcon's own malicious-macro remediation feature into a route to a SYSTEM-level command prompt, on fully patched Windows 11 25H2 and Windows Server 2025 with Falcon's highest protection tier enabled. The researcher behind it is the same person who spent August publishing bypasses for Microsoft Defender. CrowdStrike has said nothing official yet.

Three weeks ago, we covered a researcher who had just published a technique fully bypassing Microsoft's July patch for a Defender flaw - the ninth Windows zero-day from the same person since April. That researcher, who has gone by Nightmare Eclipse, MSNightmare and INFINITE NIGHTMARE across various releases, has now published a proof-of-concept under a new handle, Chaotic Eclipse, aimed at a different vendor entirely: CrowdStrike. The technique is called FalconFlank, and per BleepingComputer's reporting and The Hacker News's write-up, it claims to grant SYSTEM privileges by abusing the workflow CrowdStrike Falcon uses to remediate malicious Microsoft Office macros.

What the proof-of-concept claims to do

According to the researcher's own description, cited across multiple outlets including Security Affairs, FalconFlank works by triggering Falcon's automated response to a malicious Office macro in a way that causes the endpoint agent to spawn a command prompt running as SYSTEM - the highest local privilege level on Windows. The claimed proof-of-concept was demonstrated against a fully updated Windows 11 25H2 machine and a Windows Server 2025 machine, both protected by CrowdStrike Falcon running with "Phase 3 Optimal Protection" enabled - CrowdStrike's own highest configured protection tier, not a stripped-down or misconfigured deployment. If the claim holds up, the notable part isn't that a flaw exists somewhere in a large piece of software; it's that the flaw would sit inside the specific feature built to clean up after an attack, on the configuration customers are told represents maximum protection.

What's actually confirmed, and what isn't

Here is the honest state of the story as of publication: there is no CVE identifier, no CrowdStrike security advisory, and no vendor confirmation or patch. Cyber Security News's coverage is explicit that the claim has not been independently verified by a third party. That is a meaningfully different situation from the SonicWall or Kestra flaws we've covered this month, where CISA's own Known Exploited Vulnerabilities catalog provided independent, sourced confirmation of both the bug and its exploitation. FalconFlank right now is a named researcher's claim, backed by a demonstration video and a documented history of previously-confirmed disclosures against Microsoft products - credible enough to take seriously, not yet confirmed enough to treat as settled fact.

Why an EDR flaw doesn't wait for a CVE number

Endpoint detection and response tools occupy an unusual trust position: they run with elevated privileges specifically so they can act on threats other software can't touch, which means a flaw inside the tool itself inherits that same elevated reach. A vulnerability in a line-of-business application is bounded by that application's own privileges. A vulnerability in the agent responsible for detecting and remediating threats across an entire estate is bounded by whatever privilege that agent was granted to do its job - which, for an EDR product, is usually close to unrestricted. That asymmetry is exactly why security teams shouldn't wait for an official CVE before starting to look, even while being appropriately cautious about treating an unverified claim as confirmed fact.

What to do while the claim is unresolved

  • Review Falcon telemetry and logs for anomalous activity tied to Office macro remediation events, since that is the specific workflow the claim targets.
  • Contact your CrowdStrike account team or TAM directly for guidance rather than waiting for a public advisory - vendors often respond to direct customer enquiries about a public claim faster than they publish formal statements.
  • Do not disable or downgrade Falcon protection in response to an unverified claim; removing a working control because of an unconfirmed flaw in it is very likely a worse trade than leaving it running.
  • Track the researcher's disclosure history as a credibility signal, not a confirmation - a track record of previously-verified findings makes a new claim worth monitoring closely, not worth treating as fact before independent verification.
  • Watch specifically for a CrowdStrike advisory or CVE assignment, and for independent confirmation from a source like CISA's KEV catalog, as the point at which this moves from "claim to monitor" to "vulnerability to remediate."

Whatever CrowdStrike eventually confirms or disputes about FalconFlank itself, the pattern behind it is now a familiar one: the same researcher, working through a series of handles, keeps finding that the tools built to stop an attacker are themselves worth attacking. We covered the Defender side of that pattern in ShieldBreak's bypass of CVE-2026-50656, and the same logic applies to security infrastructure generally, not just antivirus - see our recent coverage of Check Point's SmartConsole authentication bypass. If you'd like an independent review of how your organisation would detect misuse of its own security tooling's elevated privileges, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources