Threat reportVulnerabilityTL-2026-2362
FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation DLL Hijacking
FalconFlank Zero-Day Local Privilege Escalation in (TL-2026-2362), also tracked as FalconFlank, is a high-severity software vulnerability, first published 2026-09-06. It has no confirmed attribution, affects CrowdStrike Falcon Sensor for Windows, maps to 14 MITRE ATT&CK techniques (T1003, T1012, T1036), and is covered by 9 detection rules and 4 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 4Indicators of compromise
Key facts for TL-2026-2362
- Threat ID
- TL-2026-2362
- Also known as
- FalconFlank
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, energy, defense, critical-infrastructure
- Target regions
- North America, Europe, Asia-Pacific, Middle East
- Detection rules
- 9
- Indicators of compromise
- 4
How FalconFlank Zero-Day Local Privilege Escalation in works
A local privilege escalation zero-day (dubbed 'FalconFlank') targeting CrowdStrike Falcon Sensor for Windows was publicly disclosed on September 3, 2026. The exploit abuses Falcon's 'Microsoft Office File Suspicious Macro Removal' remediation feature — which runs with SYSTEM privileges — to execute a DLL search-order hijacking attack, granting an attacker with low-privileged local access full NT AUTHORITY\SYSTEM execution. The working PoC was published by researcher 'Nightmare Eclipse' (aka Chaotic Eclipse) and independently confirmed by Kevin Beaumont. No CVE has been assigned, and no in-the-wild exploitation has been reported as of September 6, 2026.
FalconFlank is a publicly disclosed zero-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor for Windows, one of the most widely deployed endpoint detection and response (EDR) agents in enterprise environments. The exploit was released on September 3, 2026 by the prolific security researcher known as Nightmare Eclipse / Chaotic Eclipse / Infinite Nightmare / MSNightmare, who has published approximately a dozen Windows zero-day exploits since April 2026 — five of which have received CVEs and patches, and several others (including FalconFlank) remaining unpatched.
TECHNICAL MECHANISM: The vulnerability resides in CrowdStrike Falcon's 'Microsoft Office File Suspicious Macro Removal' remediation policy setting (enabled by default under Phase 3 Optimal Protection). This feature is designed to automatically detect and sanitize Office files containing malicious macros, a capability that operates with elevated SYSTEM privileges to effectively remediate threats. The exploit weaponizes this privileged code path via a multi-step DLL search-order hijacking attack:
1. TRIGGER: An attacker with existing low-privileged code execution on a target system crafts a specially formatted OLE (Office) file that triggers Falcon's macro remediation workflow. Falcon's remediation process runs with SYSTEM integrity level.
2. PRIVILEGED WRITE: By manipulating the remediation code path, the attacker causes the SYSTEM-level Falcon process to write a malicious dynamic-link library (specifically a weaponized bcrypt.dll) into the directory C:\Windows\System32\WindowsPowerShell\v1.0\ — a location that should never contain a user-supplied bcrypt.dll on a clean system (the legitimate bcrypt.dll is always loaded from C:\Windows\System32).
3. DLL SEARCH-ORDER HIJACKING: When the Falcon remediation process subsequently triggers a DLL resolution in the PowerShell v1.0 application directory context, Windows' DLL search order causes the attacker-planted bcrypt.dll to be loaded before the legitimate System32 copy. The malicious DLL executes arbitrary code with SYSTEM privileges.
4. ESCALATION COMPLETE: The attacker obtains a SYSTEM-level command prompt or can execute arbitrary code at the highest Windows integrity level, enabling full host compromise.
AFFECTED CONFIGURATIONS: The exploit has been demonstrated against fully patched Windows 11 25H2 and Windows Server 2025 (and likely Windows Server 2026) running CrowdStrike Falcon Sensor with Phase 3 Optimal Protection and the 'Microsoft Office File Suspicious Macro Removal' policy setting enabled. No specific Falcon Sensor version numbers have been confirmed — the flaw potentially affects all current sensor versions.
DETECTION ARTIFACTS: Multiple high-confidence behavioral indicators exist. The most reliable signal is the presence of bcrypt.dll in C:\Windows\System32\WindowsPowerShell\v1.0\ — on any clean system this file resolves from System32 and does not exist in that subdirectory. Additional artifacts include OLE file writes (OleFileWritten events) creating .dll or .exe files containing 'WindowsPowerShell\v1.0\' in the path, DLL writes by Falcon's remediation process into protected system directories, and suspicious SYSTEM-level process creation (Windows Event 4688) immediately following Falcon remediation events. The researcher also noted an artifact path of C:\Windows\System32\MY_SNAKE_IS_SOLID.dll reportedly created with user-controllable permissions upon execution.
MITIGATION: CrowdStrike confirmed they are 'actively investigating' and published a FalconFlank Tech Alert on their customer support portal. Their advised interim mitigation is to disable the 'Microsoft Office File Suspicious Macro Removal' Windows policy setting in the CrowdStrike Falcon console (Next-gen antivirus settings > Clean infected Microsoft Office files). The Cloud Anti-malware for Microsoft Office Files settings remain active and continue to provide protection against malicious macros even with the problematic remediation policy disabled. No code-level patch has been released as of September 6.
CONTEXT: FalconFlank is the third endpoint-security zero-day from this researcher in approximately five weeks, following HardBreacher (Kaspersky Endpoint Security, resolved via auto-update) and ShieldBreak / CVE-2026-69414 (Microsoft Defender, a full bypass of the earlier RoguePlanet patch). A recurring pattern across these exploits is that each weaponizes a security product's own remediation or privileged code path as the escalation primitive — a 'trusted-binary-abuse' class that resists traditional application allowlisting since the parent process is the legitimate security agent itself. The same researcher has been in conflict with Microsoft, who threatened legal action after the researcher began publishing zero-days against their products following frustration with Microsoft's bug bounty and vulnerability handling process. Kevin Beaumont independently confirmed FalconFlank is real and functional.
RISK ASSESSMENT: While no in-the-wild exploitation by APT groups or cybercriminal actors has been confirmed as of this writing, the public availability of a working PoC for a vulnerability in the most widely deployed EDR product in enterprise environments makes weaponization by threat actors highly probable. The exploit is especially dangerous because achieving SYSTEM privileges via Falcon's own code path allows an attacker to then disable or tamper with the very security sensor protecting the endpoint, by modifying Falcon's exclusions, policies, or agent configuration. This creates a compound risk: the defense mechanism itself becomes the attack vector.
MITRE ATT&CK techniques used in TL-2026-2362
Credential Access
Discovery
T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1036 Masquerading; T1574 Hijack Execution Flow
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Privilege Escalation
Affected products and versions in FalconFlank Zero-Day Local Privilege Escalation in
- CrowdStrike — Falcon Sensor for Windows
Vulnerable versions: All versions with Phase 3 Optimal Protection and macro removal enabled (confirmed working on current sensor versions)
Fixed in: No fixed version available - Microsoft — Windows 11
Vulnerable versions: 25H2 (fully patched as of September 2026) - Microsoft — Windows Server
Vulnerable versions: 2025 (fully patched as of September 2026); 2026 (fully patched as of September 2026)
Remediation for FalconFlank Zero-Day Local Privilege Escalation in
Patches
- No official patch available — CrowdStrike is actively investigating
Immediate actions
- Disable the 'Microsoft Office File Suspicious Macro Removal' Windows policy setting in CrowdStrike Falcon console (Next-gen antivirus settings > Clean infected Microsoft Office files)
- Hunt for bcrypt.dll in C:\Windows\System32\WindowsPowerShell\v1.0\ across all endpoints running Falcon Sensor
- Review CrowdStrike Falcon sensor and exclusions for unauthorized modifications across the fleet
- Alert SOC teams and monitor for Falcon remediation events followed by unexpected SYSTEM-level process creation (Event 4688)
Workarounds
- Disable 'Microsoft Office File Suspicious Macro Removal' policy setting (interim — Cloud Anti-malware for Microsoft Office Files retains macro protection)
- Monitor and restrict write access to C:\Windows\System32\WindowsPowerShell\v1.0\
- Isolate any FalconFlank PoC testing to isolated lab environments; do not run on production systems
Longer-term hardening
- Apply a CrowdStrike sensor code patch when released (no ETA as of September 6, 2026)
- Enforce application control policies (AppLocker / Windows Defender Application Control) to block unauthorized DLL loads from application directories
- Implement behavioral detection rules for DLL search-order hijacking patterns, particularly targeting PowerShell v1.0 and other sensitive system subdirectories
- Deploy Sysmon with FileCreate (Event 11) rule alerts for DLL writes to protected system directories
- Restrict local admin rights and enforce least-privilege principles across endpoints
- Implement UEBA to detect anomalous privileged process chains originating from security agent processes
Weaknesses (CWE) in FalconFlank Zero-Day Local Privilege Escalation in
Timeline of FalconFlank Zero-Day Local Privilege Escalation in
- Researcher Nightmare Eclipse (aka Chaotic Eclipse, MSNightmare) begins publishing Microsoft Windows zero-day exploits including LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. GitHub terminates the researcher's account in May 2026 — six early exploit repositories are wiped from the primary account but survive via forks.
- RoguePlanet zero-day disclosed against Microsoft Defender (CVE-2026-50656), a race condition vulnerability. Patched in July 2026 Patch Tuesday.
- ShieldBreak (CVE-2026-69414) disclosed — a full bypass of the RoguePlanet patch allowing local SYSTEM escalation on fully patched Windows systems with Microsoft Defender active. This is the researcher's 10th zero-day release.
- PrettyPrague disclosed — a privilege escalation exploit against GenDigital Avast Antivirus that abuses the Avast Sandbox to dump the SAM database and spawn a SYSTEM shell. First exploit from this researcher targeting a non-Microsoft product.
- HardBreacher disclosed — a privilege escalation exploit against Kaspersky Endpoint Security for Windows. Kaspersky resolved the issue via an automatic database update.
- Abstract Security publishes behavioral detection guidance focusing on: OLE file writes creating DLLs in PowerShell v1.0 directory, bcrypt.dll artifact detection in that path, broad DLL write monitoring to the same directory, and coordination-primitive detection that survives obfuscation.
- CrowdStrike advises customers to disable the 'Microsoft Office File Suspicious Macro Removal' Windows policy setting as an interim mitigation while they investigate. Cloud Anti-malware for Microsoft Office Files settings remain active.
- Kevin Beaumont independently confirms FalconFlank exploit is real and functional. CrowdStrike confirms it is actively investigating and publishes a FalconFlank Tech Alert on its customer support portal.
- FalconFlank PoC published on GitHub (Project NightCrawler) by Nightmare Eclipse. The exploit abuses CrowdStrike Falcon Sensor's Office malicious macro remediation feature to perform a DLL search-order hijacking attack via bcrypt.dll, achieving SYSTEM privileges on fully patched Windows 11 25H2 and Windows Server 2025.
- BleepingComputer, The Hacker News, and The Register publish detailed coverage of the FalconFlank zero-day. Multiple cybersecurity vendors release threat advisories and hunting guidance.
- DataBreaches.net publishes coverage of the FalconFlank vulnerability and the broader pattern of endpoint security zero-day disclosures.
- No CVE assigned. No code-level patch released by CrowdStrike. No confirmed in-the-wild exploitation reported. The only mitigation remains the policy setting disable. SOC teams continue hunting for indicators across enterprise environments.
Sources cited for FalconFlank Zero-Day Local Privilege Escalation in
- New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
- FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor
- Detection Guidance for FalconFlank
- FalconFlank Technical Analysis
- FalconFlank: CrowdStrike Falcon Sensor LPE Threat Advisory
- Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
- FalconFlank — CrowdStrike Falcon Sensor LPE (threat.wiki)
- CrowdStrike FalconFlank Tech Alert (Customer Support Portal)
- Kevin Beaumont Confirms FalconFlank (LinkedIn)
- FalconFlank PoC Repository (Project NightCrawler)
- CrowdStrike's FalconFlank Zero-Day Allows SYSTEM Privileges
Detection coverage for TL-2026-2362
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2362 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.