Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
- ID
- 21290
- Status
- summarized
- Published
- 04 Sep 2026, 2:08 AM
- Fetched
- 04 Sep 2026, 7:17 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 04 Sep 2026, 7:19 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
A researcher known as Nightmare Eclipse released a proof-of-concept privilege escalation exploit called FalconFlank targeting CrowdStrike Falcon's Microsoft Office malicious macro remediation feature. The PoC works on fully updated Windows 11 25H2 and Windows Server 2025 with Phase 3 Optimal Protection and the macro removal feature enabled. CrowdStrike advises customers to disable the 'Microsoft Office File Suspicious Macro Removal Windows policy setting' while investigating, noting cloud anti-malware settings still provide protection.
Why it matters
If your organization runs CrowdStrike Falcon with the macro removal policy enabled, disable that specific setting now and rely on cloud anti-malware instead. For everyone else, this is a reminder that endpoint security products themselves can introduce privilege escalation attack surfaces.
Discussion angle
The irony of a security product's own remediation feature becoming the attack vector — and whether your team's endpoint protection stack has been audited for this class of self-inflicted risk.