A researcher known as Chaotic Eclipse, Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE released FalconFlank, a public proof of concept claiming a zero-day local privilege-escalation flaw in the CrowdStrike Falcon Sensor. The technique allegedly abuses Falcon’s privileged remediation workflow for Microsoft Office files identified as containing malicious macros, potentially allowing a low-privileged local Windows user to execute in a more privileged—potentially SYSTEM—context.
The researcher reported successful testing on fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon with Phase 3 – Optimal Protection and the Office macro-removal capability enabled. CrowdStrike had not published an advisory, CVE, patch, or confirmation at the time of reporting; affected versions, exploit reliability, prerequisites, and mitigations remain unverified. Organizations using the specified Falcon configuration should monitor for vendor guidance and investigate whether local-access threats could abuse the remediation feature.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
In early September 2026, Nightmare Eclipse released PrettyPrague, targeting Avast and potentially other GenDigital products, and GreenSection, targeting Nvidia user-mode components. GenDigital said it fixed the Avast-related local privilege-escalation issue, while Nvidia had not responded regarding GreenSection.
Nightmare-Eclipse released HardBreacher, an unstable proof of concept for code execution in Kaspersky Endpoint Security 14.0.0.504 via NT Object Manager namespace manipulation. Kaspersky resolved the issue with a database update rather than a new product build; no CVE was assigned.
CrowdStrike said it was actively investigating the FalconFlank claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy while retaining Cloud Anti-malware for Microsoft Office Files protections. Researcher Kevin Beaumont reported confirming that the exploit works.
A researcher known as Chaotic Eclipse, Nightmare-Eclipse, and MSNightmare publicly released FalconFlank, a proof-of-concept project claiming a local privilege-escalation flaw in the CrowdStrike Falcon Sensor. The PoC allegedly abuses Falcon's high-privileged remediation process for Microsoft Office files identified as containing malicious macros.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyderes.com
Open sourcesecurityweek.com
Open sourceinfosecurity-magazine.com
Open sourcesecurityaffairs.com
Open sourceinfosec.pub
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.