Full Report
A shared security 'Nightmare'
Analysis Summary
# Vulnerability: FalconFlank Privilege Escalation
## CVE Details
- **CVE ID**: Pending (Zero-day at time of report)
- **CVSS Score**: Not yet officially rated (Estimated High)
- **CWE**: CWE-269 (Improper Privilege Management) / Logic Flaw
## Affected Systems
- **Products**: CrowdStrike Falcon Endpoint Security Platform
- **Versions**: Current versions (Confirmed on Windows 11 25H2 and Windows Server 2025)
- **Configurations**:
- Systems running "Phase 3 - Optimal Protection"
- "Microsoft Office File Suspicious Macro Removal" policy setting enabled
## Vulnerability Description
FalconFlank is a privilege escalation vulnerability that abuses the "Microsoft Office malicious macros remediation" feature. This feature is designed to automatically inspect Office documents and strip suspect macro code to prevent execution. The flaw allows an attacker to manipulate this remediation process to gain elevated system privileges. The vulnerability represents a logic flaw in how the security agent interacts with the Windows operating system during the file modification/cleaning process.
## Exploitation
- **Status**: PoC available (Published by researcher "Nightmare Eclipse"); Verified by third-party researchers (Kevin Beaumont).
- **Complexity**: Medium (Requires bypassing existing EDR detections or obfuscating the PoC).
- **Attack Vector**: Local (Requires initial access to the system to execute the PoC).
## Impact
- **Confidentiality**: High (Potential for full system access and data exfiltration).
- **Integrity**: High (Ability to modify system files and security configurations).
- **Availability**: High (Ability to disable security features or crash the system).
## Remediation
### Patches
- **CrowdStrike**: No formal patch version listed in the article, but the vendor is "actively investigating" and has issued a Tech Alert in their support portal.
- **Gen Digital (Avast/PrettyPrague)**: Actively developing a patch.
- **Kaspersky (HardBreacher)**: No response/patch status at time of report.
### Workarounds
- **CrowdStrike Recommendation**: Disable the **"Microsoft Office File Suspicious Macro Removal"** Windows policy setting.
- **Alternative Protection**: Ensure "Cloud Anti-malware for Microsoft Office Files" settings remain enabled to maintain coverage.
## Detection
- **Indicators of Compromise**:
- Execution of the `FalconFlank` PoC or derivative code.
- Unauthorized attempts to load DLLs via the Office macro remediation process.
- **Detection methods and tools**:
- Monitor for changes to the SAM database (linked to the related `PrettyPrague` exploit).
- Review CrowdStrike Falcon Tech Alerts for specific internal detection logic.
## References
- **Vendor Advisory**: CrowdStrike Support Portal (FalconFlank Tech Alert)
- **Researcher GitHub**: hxxps[://]github[.]com/MSNightmare/FalconFlank
- **Researcher GitHub (Related)**: hxxps[://]github[.]com/MSNightmare/HardBreacher
- **Researcher GitHub (Related)**: hxxps[://]github[.]com/MSNightmare/PrettyPrague
- **External Confirmation**: hxxps[://]infosec[.]exchange/@GossiTheDog@cyberplace[.]social/117207576682511216