Vulnerability
Published 2026-09-03
Verified 2026-09-19

CrowdStrike Falcon: FalconFlank local privilege-escalation demo; vendor investigating

The Hacker News (3 September 2026) reports researcher Chaotic Eclipse published FalconFlank, a public local privilege-escalation exploit demo that abuses CrowdStrike Falcon Sensor’s Office malicious-macros remediation path on fully updated Windows 11 25H2 and Windows Server 2025. The researcher said Falcon may already detect the demo code and that lab checks may need exclusions or obfuscation. A CrowdStrike spokesperson told THN the company is investigating, advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, said customers remain protected through Cloud Anti-malware for Microsoft Office Files, and pointed operators to the FalconFlank Tech Alert in the CrowdStrike support portal. Review the portal alert, apply CrowdStrike guidance, and treat the public exploit code as high-signal for endpoint labs.

Product
CrowdStrike Falcon Sensor (Windows)
Versions
Public demo claimed on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon; exact Falcon build list is in CrowdStrike’s portal Tech Alert
Exploited in Australia?
unknown
Patch to
Follow CrowdStrike FalconFlank Tech Alert; disable Microsoft Office File Suspicious Macro Removal Windows policy per vendor statement; keep Cloud Anti-malware for Office Files enabled

Primary: The Hacker News (3 Sep 2026) · Vendor: CrowdStrike (Tech Alert in support portal per THN)

vulnerabilities identity