Threat reportVulnerabilityTL-2026-2350

FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoC

highACTIVE

FalconFlank — CrowdStrike Falcon Sensor Local Privilege (TL-2026-2350) is a high-severity software vulnerability, first published 2026-09-06. It is attributed to Nightmare Eclipse with low confidence, affects CrowdStrike Falcon Sensor, maps to 11 MITRE ATT&CK techniques (T1003.001, T1053.005, T1055.001), and is covered by 9 detection rules and 7 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
1Nightmare Eclipse
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-2350

Threat ID
TL-2026-2350
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Nightmare Eclipse
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, critical-infrastructure, defense, energy, education, manufacturing, telecoms
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
7

How FalconFlank — CrowdStrike Falcon Sensor Local Privilege works

A public zero-day local privilege escalation exploit (FalconFlank) targeting the CrowdStrike Falcon Sensor was released on September 3, 2026 by the anonymous researcher Nightmare Eclipse. The exploit weaponizes Falcon's Office malicious macro removal remediation feature using a KTM-transacted DLL planting technique (oplock + reparse point race) to escalate from limited local access to full SYSTEM privileges on fully updated Windows 11 25H2 and Windows Server 2025. Kevin Beaumont independently confirmed the exploit works. CrowdStrike is investigating and has advised customers to disable the Microsoft Office File Suspicious Macro Removal policy as an interim mitigation. No CVE has been assigned and no fix is available.

FalconFlank is a local privilege escalation (LPE) zero-day exploit targeting the CrowdStrike Falcon Sensor, publicly released on September 3, 2026 by the anonymous security researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse, Infinite Nightmare, Dead Eclipse, and MSNightmare). The exploit weaponizes Falcon's Microsoft Office malicious macro removal remediation feature — an automated security mechanism designed to inspect Office documents and strip suspicious macro code at SYSTEM privilege level — turning it into a privilege escalation vector through a race-condition DLL planting attack. Kevin Beaumont independently confirmed the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 running CrowdStrike Falcon with Phase 3 Optimal Protection policies and the Office macro removal feature enabled.

The technical exploit chain combines multiple Windows subsystem abuse techniques. First, the exploit creates a staged directory structure under %TEMP% with the path %TEMP%\Flanker_{GUID}\WindowsPowerShell\v1.0\bcrypt.dll and writes a 93,696-byte OLE2 Compound Document (rawData) containing embedded VBA macros (Project.ThisDocument.autoopen) into that staged file — this OLE2 document serves as the trigger file that CrowdStrike Falcon's Office macro remediation feature detects and acts upon. The exploit then takes an opportunistic lock (OPLOCK via FSCTL_REQUEST_OPLOCK) on the staged file to create a time-of-check/time-of-use (TOCTOU) race window. It deletes the intermediate v1.0 directory via NtSetInformationFile with FileDispositionInfoEx and replaces it with a mount point reparse point (IO_REPARSE_TAG_MOUNT_POINT) that redirects filesystem operations from the temp staging path to the real system path at \SystemRoot\System32\WindowsPowerShell. Using a Kernel Transaction Manager (KTM) transacted file operation — CreateFileTransacted followed by CommitTransaction — the exploit atomically overwrites the real C:\Windows\System32\WindowsPowerShell\v1.0\bcrypt.dll with the FlankerDll payload written via memory-mapped file (CreateFileMapping, MapViewOfFile, memmove). After committing the transaction, the exploit triggers the MareBackup scheduled task under \Microsoft\Windows\Application Experience via the Task Scheduler COM interface (CLSID_TaskScheduler, IRegisteredTask::Run), which loads bcrypt.dll from the now-compromised path at SYSTEM integrity level. A named pipe (\??\pipe\FALCONFLANK) is created for inter-process communication between the low-privileged exploiter and the planted SYSTEM-level DLL. On a clean system, bcrypt.dll always resolves from System32 and never legitimately appears in the WindowsPowerShell\v1.0\ directory, making its presence there a high-confidence detection artifact effectively free of false positives.

This exploit is part of a broader campaign by Nightmare Eclipse against the endpoint security industry. The same week, the researcher released three additional zero-days: HardBreacher (Kaspersky Antivirus for Endpoint LPE, subsequently resolved by Kaspersky via automatic database update), PrettyPrague (GenDigital Avast Antivirus LPE with SAM database dumping capability, under active patch development), and GreenSection (Nvidia driver memory corruption denial-of-service). Since April 2026, Nightmare Eclipse has disclosed over a dozen zero-days — including BlueHammer (CVE-2026-33825, Windows Defender LPE, added to CISA KEV), RedSun (CVE-2026-41091, patched out-of-band May 2026), UnDefend (CVE-2026-45498, patched out-of-band May 2026), YellowKey (CVE-2026-45585, patched June 2026), GreenPlasma (CVE-2026-45586, patched June 2026), RoguePlanet (CVE-2026-50656, Microsoft Malware Protection Engine LPE, patched July 2026), and LegacyHive (CVE-2026-62832, Windows User Profile Service, unpatched) — primarily targeting Microsoft products before expanding to the broader endpoint security ecosystem. Microsoft has publicly warned of legal action against the researcher. Huntress observed in-the-wild exploitation of BlueHammer, RedSun, and UnDefend in April 2026. No CVE has been assigned to FalconFlank as of this writing, CrowdStrike is actively investigating, and no fix is available. CrowdStrike has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as an interim mitigation while emphasizing that customers remain protected through Cloud Anti-malware for Microsoft Office Files settings. A FalconFlank Tech Alert is available in the CrowdStrike support portal (requires support portal account). No confirmed in-the-wild exploitation of FalconFlank has been reported, though with a public, independently confirmed PoC widely available, threat actor adoption is anticipated.

MITRE ATT&CK techniques used in TL-2026-2350

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory

Privilege Escalation

T1053.005 Scheduled Task/Job: Scheduled Task

Defense Evasion

T1055.001 Dynamic-link Library Injection; T1574.001 DLL

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in FalconFlank — CrowdStrike Falcon Sensor Local Privilege

  • CrowdStrike — Falcon Sensor
    Vulnerable versions: All versions with Office macro remediation feature enabled; Phase 3 Optimal Protection policy configuration
  • Microsoft — Windows 11
    Vulnerable versions: 25H2 (fully updated)
  • Microsoft — Windows Server
    Vulnerable versions: 2025 (fully updated)

Remediation for FalconFlank — CrowdStrike Falcon Sensor Local Privilege

Immediate actions

  • Disable the Microsoft Office File Suspicious Macro Removal Windows policy setting in CrowdStrike Falcon sensor policies
  • Review the FalconFlank Tech Alert in the CrowdStrike support portal for updated vendor guidance
  • Deploy Sysmon Event ID 11 file creation monitoring targeting \WindowsPowerShell\v1.0\bcrypt.dll across all endpoints
  • Enable CrowdStrike Falcon Data Replicator (FDR) telemetry collection for OleFileWritten events with DLL/EXE extensions
  • Scan all endpoints for presence of bcrypt.dll in C:\Windows\System32\WindowsPowerShell\v1.0\
  • Inventory and review ANY unexpected DLLs in C:\Windows\System32\WindowsPowerShell\v1.0\ outside the Modules subtree

Workarounds

  • Disable Microsoft Office File Suspicious Macro Removal policy as interim workaround until patch available (note: this reduces macro-based threat detection)
  • Enable and enforce CrowdStrike Cloud Anti-malware for Microsoft Office Files settings as compensating control
  • Restrict local interactive access and enforce least-privilege principles to reduce LPE attack surface
  • Implement application control policies blocking unsigned DLLs in WindowsPowerShell\v1.0\
  • Monitor named pipe creation for \??\pipe\FALCONFLANK as a secondary detection signal

Longer-term hardening

  • Apply CrowdStrike Falcon Sensor patch when released
  • Implement behavioral detection rules for TEMP-directory-to-System32 mount point redirection sequences
  • Monitor for MareBackup scheduled task executions triggered from non-privileged user contexts
  • Review and harden endpoint security agent configuration — restrict unnecessary remediation features
  • Establish proactive monitoring for OPLOCK + reparse point abuse chains across EDR telemetry
  • Adopt multi-layered endpoint protection strategy to diversify coverage against single-vendor zero-days

Weaknesses (CWE) in FalconFlank — CrowdStrike Falcon Sensor Local Privilege

CWE-367, CWE-427, CWE-269, CWE-59

Timeline of FalconFlank — CrowdStrike Falcon Sensor Local Privilege

  • Nightmare Eclipse's BlueHammer (CVE-2026-33825) Windows Defender LPE patched by Microsoft, added to CISA KEV; Huntress observed in-the-wild exploitation
  • RoguePlanet (CVE-2026-50656) Microsoft Malware Protection Engine LPE patched out-of-band by Microsoft — same researcher's prior endpoint-security zero-day
  • SocRadar publishes initial analysis of FalconFlank; The Register reports on the exploit chain
  • Nightmare Eclipse publishes three additional zero-days same day: HardBreacher (Kaspersky LPE), PrettyPrague (Avast LPE with SAM dumping), GreenSection (Nvidia DoS)
  • Nightmare Eclipse publishes FalconFlank PoC on GitHub and Project NightCrawler — CrowdStrike Falcon Sensor LPE zero-day abusing Office macro remediation feature
  • BleepingComputer publishes detailed FalconFlank article with CrowdStrike statement and mitigation guidance
  • Abstract Security publishes FalconFlank detection guidance with FDR and Sysmon-based rules including OleFileWritten monitoring and bcrypt.dll hunt
  • CrowdStrike issues FalconFlank Tech Alert via support portal, advises customers to disable Microsoft Office File Suspicious Macro Removal Windows policy setting
  • Kevin Beaumont independently confirms FalconFlank exploit works on fully updated Windows 11 25H2 and Windows Server 2025
  • Threat Wiki publishes technical FalconFlank analysis; source code review confirms KTM transacted write, OPLOCK race, reparse point mount junction, and MareBackup Task Scheduler trigger
  • Blackswan Cybersecurity publishes threat advisory assessing FalconFlank business risk as high if validated; no confirmed in-the-wild exploitation at time of reporting

Sources cited for FalconFlank — CrowdStrike Falcon Sensor Local Privilege

Detection coverage for TL-2026-2350

As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2350 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats