
An anonymous security researcher using the “Nightmare Eclipse” handle has discovered a CrowdStrike Falcon zero-day exploit called “Falcon Flank“, which allows attackers to escalate their privileges on current Windows systems.
According to Nightmare Eclipse, the new vulnerability (which has not yet been assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike’s endpoint security platform.
A successful exploitation allows attackers to create a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon’s malicious Office macro remediation feature.
“FalconFlank is a 0-day privilege escalation that abuses the fix for malicious office macros in Crowdstrike Falcon Sensor. Apparently, at the time I publish this, Crowdstrike would already have detections for it, so if you want to test, you’ll either need to add it to the exclusions or obfuscate the PoC and change the DLL loading technique.” Nightmare Eclipse said. “As of now it works in a fully updated Windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon.”
When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company was investigating the researcher’s claims and advised customers to disable the Microsoft Office Windows policy setting that turns on the suspicious macro removal feature in the security software.
“We are actively investigating these claims and advise customers to disable the Windows policy setting to remove suspicious macros in Microsoft Office files,” the spokesperson told BleepingComputer. “Customers remain protected by Cloud Anti-Malware settings for Microsoft Office files. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.”
Although the company also shared this link As for the technical alert about the FalconFlank zero-day exploit, the advisory is not public and customers can only access it if they have an account in the CrowdStrike support portal.
CrowdStrike has not yet responded to a second email requesting a copy of the FalconFlank tech alert and whether the FalconFlank vulnerability has been assigned a CVE ID.
Kaspersky, Avast, Nvidia and Microsoft Zero Days
This week Nightmare Eclipse also released zero-day privilege escalation exploits for Kaspersky Antivirus for Endpoint (called…). HardBreacher) and GenDigital Avast Antivirus (PrettyPrague) as well as a denial of service zero day for Nvidia (called Green section), which causes the system to crash.
Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by Nightmare Eclipse this week are real and working.
Nightmare Eclipse has also uncovered multiple zero-day exploits since April that target multiple Microsoft products, including Microsoft Defender, BitLocker, and various other Windows components.
These Microsoft zero-days are known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and Remove defense. While the vulnerabilities in LegacyHive, RoguePlanet, YellowKey, GreenPlasma and MiniPlasma have now been fixed, the other zero-day vulnerabilities remain and are still awaiting an official patch.
After Nightmare Eclipse, Microsoft revealed the first zero days replied with Warnings of legal action against people who “conduct malicious activities that cause real harm to our customers,” leading many to believe that the company was directly threatening the security researcher.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

