# FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoC

> A public zero-day local privilege escalation exploit (FalconFlank) targeting the CrowdStrike Falcon Sensor was released on September 3, 2026 by the anonymous researcher Nightmare Eclipse. The exploit weaponizes Falcon's Office malicious macro removal remediation feature using a KTM-transacted DLL planting technique (oplock + reparse point race) to escalate from limited local access to full SYSTEM privileges on fully updated Windows 11 25H2 and Windows Server 2025. Kevin Beaumont independently confirmed the exploit works. CrowdStrike is investigating and has advised customers to disable the Microsoft Office File Suspicious Macro Removal policy as an interim mitigation. No CVE has been assigned and no fix is available.

- **Published:** 2026-09-06T00:00:00Z
- **Last reviewed:** 2026-09-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2350
- **ID:** TL-2026-2350
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Nightmare Eclipse
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FalconFlank is a local privilege escalation (LPE) zero-day exploit targeting the CrowdStrike Falcon Sensor, publicly released on September 3, 2026 by the anonymous security researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse, Infinite Nightmare, Dead Eclipse, and MSNightmare). The exploit weaponizes Falcon's Microsoft Office malicious macro removal remediation feature — an automated security mechanism designed to inspect Office documents and strip suspicious macro code at SYSTEM privilege level — turning it into a privilege escalation vector through a race-condition DLL planting attack. Kevin Beaumont independently confirmed the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 running CrowdStrike Falcon with Phase 3 Optimal Protection policies and the Office macro removal feature enabled.

The technical exploit chain combines multiple Windows subsystem abuse techniques. First, the exploit creates a staged directory structure under %TEMP% with the path %TEMP%\Flanker_{GUID}\WindowsPowerShell\v1.0\bcrypt.dll and writes a 93,696-byte OLE2 Compound Document (rawData) containing embedded VBA macros (Project.ThisDocument.autoopen) into that staged file — this OLE2 document serves as the trigger file that CrowdStrike Falcon's Office macro remediation feature detects and acts upon. The exploit then takes an opportunistic lock (OPLOCK via FSCTL_REQUEST_OPLOCK) on the staged file to create a time-of-check/time-of-use (TOCTOU) race window. It deletes the intermediate v1.0 directory via NtSetInformationFile with FileDispositionInfoEx and replaces it with a mount point reparse point (IO_REPARSE_TAG_MOUNT_POINT) that redirects filesystem operations from the temp staging path to the real system path at \SystemRoot\System32\WindowsPowerShell. Using a Kernel Transaction Manager (KTM) transacted file operation — CreateFileTransacted followed by CommitTransaction — the exploit atomically overwrites the real C:\Windows\System32\WindowsPowerShell\v1.0\bcrypt.dll with the FlankerDll payload written via memory-mapped file (CreateFileMapping, MapViewOfFile, memmove). After committing the transaction, the exploit triggers the MareBackup scheduled task under \Microsoft\Windows\Application Experience via the Task Scheduler COM interface (CLSID_TaskScheduler, IRegisteredTask::Run), which loads bcrypt.dll from the now-compromised path at SYSTEM integrity level. A named pipe (\??\pipe\FALCONFLANK) is created for inter-process communication between the low-privileged exploiter and the planted SYSTEM-level DLL. On a clean system, bcrypt.dll always resolves from System32 and never legitimately appears in the WindowsPowerShell\v1.0\ directory, making its presence there a high-confidence detection artifact effectively free of false positives.

This exploit is part of a broader campaign by Nightmare Eclipse against the endpoint security industry. The same week, the researcher released three additional zero-days: HardBreacher (Kaspersky Antivirus for Endpoint LPE, subsequently resolved by Kaspersky via automatic database update), PrettyPrague (GenDigital Avast Antivirus LPE with SAM database dumping capability, under active patch development), and GreenSection (Nvidia driver memory corruption denial-of-service). Since April 2026, Nightmare Eclipse has disclosed over a dozen zero-days — including BlueHammer (CVE-2026-33825, Windows Defender LPE, added to CISA KEV), RedSun (CVE-2026-41091, patched out-of-band May 2026), UnDefend (CVE-2026-45498, patched out-of-band May 2026), YellowKey (CVE-2026-45585, patched June 2026), GreenPlasma (CVE-2026-45586, patched June 2026), RoguePlanet (CVE-2026-50656, Microsoft Malware Protection Engine LPE, patched July 2026), and LegacyHive (CVE-2026-62832, Windows User Profile Service, unpatched) — primarily targeting Microsoft products before expanding to the broader endpoint security ecosystem. Microsoft has publicly warned of legal action against the researcher. Huntress observed in-the-wild exploitation of BlueHammer, RedSun, and UnDefend in April 2026. No CVE has been assigned to FalconFlank as of this writing, CrowdStrike is actively investigating, and no fix is available. CrowdStrike has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting as an interim mitigation while emphasizing that customers remain protected through Cloud Anti-malware for Microsoft Office Files settings. A FalconFlank Tech Alert is available in the CrowdStrike support portal (requires support portal account). No confirmed in-the-wild exploitation of FalconFlank has been reported, though with a public, independently confirmed PoC widely available, threat actor adoption is anticipated.

## MITRE ATT&CK

- T1574.001 DLL
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1685 Disable or Modify Tools
- T1204.002 User Execution: Malicious File
- T1055.001 Dynamic-link Library Injection
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1003.001 OS Credential Dumping: LSASS Memory
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1082 System Information Discovery
- T1057 Process Discovery

## Sources

- [CrowdStrike FalconFlank Tech Alert (support portal login required)](https://supportportal.crowdstrike.com/)
- [New CrowdStrike FalconFlank zero-day grants SYSTEM privileges](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/)
- [Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC](https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318)
- [FalconFlank Detection Guidance — Abstract Security](https://www.abstract.security/blog/chaotic-eclipse-releases-crowdstrike-falcon-zero-day-falconflank-detection-guidance)
- [FalconFlank PoC Repository (MSNightmare/FalconFlank on GitHub)](https://github.com/MSNightmare/FalconFlank)
- [FalconFlank — CrowdStrike Falcon 0day PoC (Project NightCrawler mirror)](https://git.projectnightcrawler.dev/NightmareEclipse/FalconFlank)
- [Threat Advisory: CrowdStrike Falcon Sensor LPE Zero-Day (Blackswan Cybersecurity)](https://blackswan-cybersecurity.com/threat-advisory-crowdstrike-falcon-sensor-local-privilege-escalation-zero-day-falconflank-august-26-2026/)
- [FalconFlank Analysis — Threat Wiki](https://threat.wiki/ops/falconflank-crowdstrike-falcon-privilege-escalation-chaotic-eclipse-september-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2350
