CrowdStrike Falcon: FalconFlank local privilege-escalation demo; vendor investigating
The Hacker News (3 September 2026) reports researcher Chaotic Eclipse published FalconFlank, a public local privilege-escalation exploit demo that abuses CrowdStrike Falcon Sensor’s Office malicious-macros remediation path on fully updated Windows 11 25H2 and Windows Server 2025. The researcher said Falcon may already detect the demo code and that lab checks may need exclusions or obfuscation. A CrowdStrike spokesperson told THN the company is investigating, advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, said customers remain protected through Cloud Anti-malware for Microsoft Office Files, and pointed operators to the FalconFlank Tech Alert in the CrowdStrike support portal. Review the portal alert, apply CrowdStrike guidance, and treat the public exploit code as high-signal for endpoint labs.
- Product
- CrowdStrike Falcon Sensor (Windows)
- Versions
- Public demo claimed on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon; exact Falcon build list is in CrowdStrike’s portal Tech Alert
- Exploited in Australia?
- unknown
- Patch to
- Follow CrowdStrike FalconFlank Tech Alert; disable Microsoft Office File Suspicious Macro Removal Windows policy per vendor statement; keep Cloud Anti-malware for Office Files enabled
Primary: The Hacker News (3 Sep 2026) · Vendor: CrowdStrike (Tech Alert in support portal per THN)
