sign posted exterior CrowdStrike office July 30
A sign is posted on the exterior of a CrowdStrike office on July 30, 2024 in Sunnyvale, California.

A researcher who has spent months systematically exploiting the security software trusted to protect Windows machines turned the same approach against CrowdStrike Falcon this week, publishing working exploit code for a previously unknown privilege-escalation flaw. The vulnerability abuses Falcon's document-cleanup routine to deliver full SYSTEM-level access on fully patched Windows 11 and Windows Server 2025 endpoints. CrowdStrike confirmed that it is investigating the issue and issued an immediate mitigation for its 88,000-plus customer organisations, including 62% of the Fortune 500.

The exploit, published on GitHub on September 3, 2026, is called FalconFlank. It was developed by a researcher known as Chaotic Eclipse, who also uses the aliases INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse. The disclosure is the latest in what threat-intelligence firms now classify as a documented campaign targeting the remediation workflows of Windows security software. Every major tool that protects Windows endpoints runs with elevated privileges; that architectural necessity has become the researcher's primary attack surface. FalconFlank is notable because CrowdStrike Falcon has the largest customer base targeted in the campaign so far.

Disclosures made by the same researcher during the week extended the campaign to two other major security vendors. HardBreacher, which targeted Kaspersky Endpoint Security for Windows version 14.0.0.504, was addressed by Kaspersky through an automatic database update after the researcher alerted The Hacker News. PrettyPrague, a privilege-escalation flaw in Avast Antivirus that can dump the Windows SAM database and spawn a full SYSTEM shell on fully patched Windows 11, prompted Gen Digital — Avast's parent company, which also owns AVG and Norton — to confirm the vulnerability and begin developing a patch.

The common factor in all these cases is an architectural reality that no individual security vendor can fully eliminate: effective endpoint security requires elevated privileges, while privileged remediation workflows that interact with the file system create trust boundaries that attackers can redirect. Enterprise defenders should treat this as an ongoing category of risk rather than a series of unrelated bugs.

How Falcon's Own Cleanup Routine Becomes a Privilege Elevator

The vulnerability targets a specific Falcon capability: the automatic removal of malicious macros from Microsoft Office files. Falcon's macro-removal feature is a core part of its active-protection suite and runs as a Windows service with SYSTEM-level privileges — the highest trust level in Windows, above administrator.

The attack exploits the gap between what a standard user account can do and what a SYSTEM-level service is trusted to do. According to the public proof-of-concept code and analysis by SOCRadar, the exploit chain involves four documented Windows attack primitives: named-pipe manipulation, NTFS reparse-point redirection, DLL injection and Windows system API calls. Broadly, a low-privileged attacker positions malicious content so that when Falcon's remediation routine performs privileged file operations, it acts on attacker-controlled content instead of the legitimate file it expects to find. The security agent's trust becomes the attacker's privilege.

SOCRadar's analysis notes that the named-pipe reparse-point attack chain and the specific root cause — whether a misconfigured security descriptor, a race condition between the check and the action, or unsafe file-path resolution — have not been publicly documented. No CVE identifier or CVSS severity score has been assigned. What is documented is the precondition: the exploit requires Windows 11 25H2 or Windows Server 2025, CrowdStrike Falcon configured for Phase 3 Optimal Protection, and the Microsoft Office file malicious-macro removal policy enabled. This is a common configuration for organisations relying on Falcon to secure Office documents.

One important caveat from SOCRadar's independent review is that the researcher's GitHub README acknowledges CrowdStrike may already have deployed behavioural detections targeting the specific proof-of-concept technique by the time the code was published. The underlying vulnerability may persist even if Falcon blocks the exact technique demonstrated. An attacker encountering those detections would need only to change the DLL-loading method or add the executable to Falcon exclusions, rather than redesign the underlying exploit concept.

CrowdStrike's Response: Disable the Policy, Check the Portal

In a statement to The Hacker News, a CrowdStrike spokesperson confirmed the investigation and issued the following guidance: customers should disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as an immediate mitigation.

The statement added that organisations remain protected through the Cloud Anti-malware for Microsoft Office Files settings and directed customers to a dedicated FalconFlank Tech Alert in the CrowdStrike support portal for environment-specific guidance. No remediated sensor version has been released, and no formal CVE has been issued.

The mitigation involves a real trade-off: disabling macro removal reduces one layer of Office-document protection while the underlying vulnerability exists. Organisations should review the FalconFlank Tech Alert in the support portal for specific guidance on their Falcon configuration before deciding how to balance that exposure.

Why a Flaw in Security Software Is Worse Than a Flaw in Most Other Applications

A privilege-escalation vulnerability in ordinary user software is serious. The same vulnerability in an EDR agent is structurally worse because of how endpoint-security software works.

EDR and antivirus agents must run with elevated system privileges by design. To intercept malicious activity before it executes, an agent needs to operate at or above the attacker's privilege level. That is what makes EDR effective at stopping malware, but it also makes EDR a high-value target. When a security agent is manipulated into acting on attacker-controlled content, the attacker gains privileges that bypass every downstream defence, including the agent itself. An attacker who obtains SYSTEM access can move laterally across the network with the implicit trust of an authorised security service — reading and modifying memory, accessing credential stores and disabling the Falcon sensor.

The attack surface is widened further by the precondition: macro removal is a common enterprise configuration for organisations relying on Falcon to detect malicious Office documents. No unusual or non-default setting is required.

What Enterprise Defenders Should Do Now

Organisations running CrowdStrike Falcon on Windows 11 25H2 or Windows Server 2025 with the macro-removal policy active should take the following steps immediately:

Disable the Microsoft Office File Suspicious Macro Removal Windows policy setting in Falcon, as CrowdStrike has explicitly recommended. This is the vendor's current short-term mitigation.

Review the FalconFlank Tech Alert in the CrowdStrike support portal. The alert contains environment-specific guidance and will be updated as the investigation develops.

Confirm that Cloud Anti-malware for Microsoft Office Files settings remain active. CrowdStrike's statement indicates that this provides continued document-level protection while the macro-removal policy is disabled.

Audit local access controls on sensitive Windows endpoints. FalconFlank requires an attacker to already have a local foothold — either a logged-in session, a previously compromised account or physical access. Limiting who can authenticate locally or through Remote Desktop reduces the number of machines where exploitation is viable.

Monitor for abnormal SYSTEM-level process activity from Falcon-related processes. The public proof of concept creates a named pipe containing the string "FALCONFLANK" — a low-confidence behavioural indicator that threat-hunting teams can include in detection queries while official Sigma rules are developed.

Apply Falcon sensor updates as soon as CrowdStrike releases a remediated version. No patch is currently available. CrowdStrike will communicate its availability through the support portal.

Does Disabling Macro Protection Leave Machines Exposed? — And Other Security Trade-offs

Disabling the Microsoft Office File Suspicious Macro Removal Windows policy does not disable all Falcon protection against Office-based threats. CrowdStrike's mitigation explicitly notes that Cloud Anti-malware protection remains active, providing detection coverage at a different layer of the document-processing pipeline. The disabled feature is active macro stripping during remediation — the process that runs with the elevated privileges abused by FalconFlank. Organisations should verify that their Cloud Anti-malware settings are properly configured and consult the FalconFlank Tech Alert before making broader changes to their Falcon policy.

Remediation Workflows: Security Software's Structural Attack Surface

FalconFlank is not an isolated bug. It belongs to a documented class of exploits targeting the file-remediation workflows of Windows security software. These exploits have appeared repeatedly since April 2026 and share the same underlying logic: when a trusted service with elevated privileges performs file operations, an attacker who can influence those operations inherits that trust.

The same researcher's previous disclosures map the extent of this attack surface. BlueHammer (CVE-2026-33825), which targeted Windows Defender's signature-update workflow, was patched in April 2026 and confirmed exploited in the wild. Huntress Labs said BlueHammer was used by threat actors operating infrastructure geolocated to Russia. CISA added it to the Known Exploited Vulnerabilities catalogue on April 22, 2026.

RedSun, for which no CVE has been assigned, targeted another part of Defender's remediation logic — specifically the way Defender handles files marked with a Cloud Files placeholder tag. It allowed an attacker to redirect Defender's privileged restoration operation to a system location containing attacker-controlled content. ShieldBreak (CVE-2026-69414), disclosed on August 12, 2026, demonstrated a bypass of Microsoft's patch for the earlier RoguePlanet vulnerability. It used the Windows Cloud Filter API, Object Manager symlinks, Common Log File System manipulation and a Windows Error Reporting scheduled task to load an attacker-controlled library with SYSTEM privileges. The ShieldBreak technical attack chain has been independently confirmed. As of September 5, 2026, Microsoft had not released a patch for the ShieldBreak CVE-2026-69414 patch bypass.

Is Chaotic Eclipse / Nightmare-Eclipse a Threat Actor or a Researcher?

Barracuda's threat-intelligence team issued a Nightmare-Eclipse threat-actor profile in May 2026, concluding that Nightmare-Eclipse should be treated as a malicious actor rather than a neutral researcher or whistleblower, despite operating without a traditional profit motive or nation-state affiliation. The distinction matters to defenders because it affects how they should triage the disclosures.

The researcher's stated motivation, documented in blog posts, is personal grievance. Posts on the blog describe being "left homeless with nothing" following a conflict with Microsoft and allege that personnel at the Microsoft Security Response Center directly threatened them. Whether the conflict involved an employment relationship, a contractor arrangement or an external researcher whose reports were mishandled remains unverified. What is documented is that the researcher's knowledge of Windows internals — particularly the file system, security-service privilege models and the IPC mechanisms connecting them — is consistent with someone who has had deep, sustained access to that codebase.

The Nightmare-Eclipse campaign began with exploits targeting Microsoft. The expansion to third-party security vendors — Kaspersky, Avast and CrowdStrike — was announced in the researcher's own blog posts as a deliberate escalation, with a stated intention to "drag other companies into this". The week of September 1–5, 2026, provided the clearest demonstration of that promise.

Huntress Labs confirmed that BlueHammer and other Nightmare-Eclipse tools were incorporated into intrusion attempts linked to Russian infrastructure within days of their release. Threat-intelligence analysis documented attackers chaining Nightmare-Eclipse Defender exploits with ransomware deployment as the end goal. The prior disclosures were not merely theoretical: the tools were picked up, weaponised and deployed.

What Can't Disabling the Macro Policy Protect Against?

The immediate mitigation — disabling the macro-removal policy — addresses only the specific attack path used by FalconFlank. It does not address:

  • The broader class of EDR-remediation exploits that may be developed against other Falcon features running with elevated privileges
  • ShieldBreak (CVE-2026-69414) and other Nightmare-Eclipse disclosures that remain unpatched in Microsoft Defender
  • Future disclosures: the researcher has explicitly threatened additional releases, including claimed remote-code-execution vulnerabilities

Enterprise security teams should monitor CrowdStrike's support portal for the formal patch, maintain the mitigation until it arrives and use behavioural detection — looking for standard-user processes interacting with Falcon-related files, services or named pipes — as a compensating control in the interim. Network-layer detection and identity controls that operate independently of the endpoint provide the most reliable compensating coverage for a compromised endpoint agent, according to Barracuda's defensive recommendations for Nightmare-Eclipse.


Frequently Asked Questions

What exactly does FalconFlank do, and who is at risk?

FalconFlank is a proof-of-concept exploit demonstrating a privilege-escalation path in CrowdStrike Falcon Sensor for Windows. It abuses Falcon's feature that automatically removes malicious macros from Microsoft Office documents — a remediation routine that runs with SYSTEM-level privileges. By using named-pipe manipulation, NTFS reparse points and DLL injection, the exploit tricks the privileged routine into acting on attacker-controlled content, giving a low-privileged attacker with an existing local foothold full SYSTEM access. Organisations at direct risk are those running Falcon on Windows 11 25H2 or Windows Server 2025 with the Microsoft Office File Suspicious Macro Removal policy enabled and Phase 3 Optimal Protection active. As of September 5, 2026, no CVE had been assigned and no patch had been released.

Should my organisation disable the CrowdStrike macro-removal policy right now?

CrowdStrike has explicitly recommended disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting as an immediate mitigation. The company says that Cloud Anti-malware for Microsoft Office Files settings provide continued document-level protection while the macro-removal feature is disabled. Organisations should review the FalconFlank Tech Alert in the CrowdStrike support portal for environment-specific guidance before changing the configuration and should apply the remediated sensor version as soon as CrowdStrike releases one.

Has FalconFlank been used in real attacks?

No confirmed in-the-wild exploitation of FalconFlank had been reported as of September 5, 2026. However, the same researcher's previous exploits targeting Windows Defender — specifically BlueHammer, which was added to CISA's Known Exploited Vulnerabilities catalogue — were confirmed to have been weaponised in real intrusion activity within days of release, with infrastructure geolocated to Russia involved. Security researchers have documented a pattern of attackers rapidly incorporating Nightmare-Eclipse tools after publication. FalconFlank should be treated as a credible and urgent threat, not a theoretical one.

Why does security software keep becoming an attack target, and is this likely to continue?

EDR and antivirus tools necessarily run with SYSTEM-level or kernel-level privileges on Windows; otherwise, they cannot intercept malware before it executes. This makes their remediation workflows a structural attack surface: any feature that performs privileged file operations can potentially be redirected through named-pipe manipulation, NTFS junctions or similar techniques. FalconFlank, HardBreacher, PrettyPrague, ShieldBreak, RedSun and BlueHammer all exploit this same architectural reality across different vendors and remediation features. The Nightmare-Eclipse researcher has explicitly stated an intention to continue publishing exploits and has threatened remote-code-execution vulnerabilities in addition to the local privilege-escalation tools released so far. Defenders should treat this as an ongoing campaign and invest in detection and identity controls that operate independently of the endpoint agent.

Originally published on Tech Times