# FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation DLL Hijacking

> A local privilege escalation zero-day (dubbed 'FalconFlank') targeting CrowdStrike Falcon Sensor for Windows was publicly disclosed on September 3, 2026. The exploit abuses Falcon's 'Microsoft Office File Suspicious Macro Removal' remediation feature — which runs with SYSTEM privileges — to execute a DLL search-order hijacking attack, granting an attacker with low-privileged local access full NT AUTHORITY\SYSTEM execution. The working PoC was published by researcher 'Nightmare Eclipse' (aka Chaotic Eclipse) and independently confirmed by Kevin Beaumont. No CVE has been assigned, and no in-the-wild exploitation has been reported as of September 6, 2026.

- **Published:** 2026-09-06T00:00:00Z
- **Last reviewed:** 2026-09-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2362
- **ID:** TL-2026-2362
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 4 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FalconFlank is a publicly disclosed zero-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor for Windows, one of the most widely deployed endpoint detection and response (EDR) agents in enterprise environments. The exploit was released on September 3, 2026 by the prolific security researcher known as Nightmare Eclipse / Chaotic Eclipse / Infinite Nightmare / MSNightmare, who has published approximately a dozen Windows zero-day exploits since April 2026 — five of which have received CVEs and patches, and several others (including FalconFlank) remaining unpatched.

TECHNICAL MECHANISM: The vulnerability resides in CrowdStrike Falcon's 'Microsoft Office File Suspicious Macro Removal' remediation policy setting (enabled by default under Phase 3 Optimal Protection). This feature is designed to automatically detect and sanitize Office files containing malicious macros, a capability that operates with elevated SYSTEM privileges to effectively remediate threats. The exploit weaponizes this privileged code path via a multi-step DLL search-order hijacking attack:

1. TRIGGER: An attacker with existing low-privileged code execution on a target system crafts a specially formatted OLE (Office) file that triggers Falcon's macro remediation workflow. Falcon's remediation process runs with SYSTEM integrity level.

2. PRIVILEGED WRITE: By manipulating the remediation code path, the attacker causes the SYSTEM-level Falcon process to write a malicious dynamic-link library (specifically a weaponized bcrypt.dll) into the directory C:\Windows\System32\WindowsPowerShell\v1.0\ — a location that should never contain a user-supplied bcrypt.dll on a clean system (the legitimate bcrypt.dll is always loaded from C:\Windows\System32).

3. DLL SEARCH-ORDER HIJACKING: When the Falcon remediation process subsequently triggers a DLL resolution in the PowerShell v1.0 application directory context, Windows' DLL search order causes the attacker-planted bcrypt.dll to be loaded before the legitimate System32 copy. The malicious DLL executes arbitrary code with SYSTEM privileges.

4. ESCALATION COMPLETE: The attacker obtains a SYSTEM-level command prompt or can execute arbitrary code at the highest Windows integrity level, enabling full host compromise.

AFFECTED CONFIGURATIONS: The exploit has been demonstrated against fully patched Windows 11 25H2 and Windows Server 2025 (and likely Windows Server 2026) running CrowdStrike Falcon Sensor with Phase 3 Optimal Protection and the 'Microsoft Office File Suspicious Macro Removal' policy setting enabled. No specific Falcon Sensor version numbers have been confirmed — the flaw potentially affects all current sensor versions.

DETECTION ARTIFACTS: Multiple high-confidence behavioral indicators exist. The most reliable signal is the presence of bcrypt.dll in C:\Windows\System32\WindowsPowerShell\v1.0\ — on any clean system this file resolves from System32 and does not exist in that subdirectory. Additional artifacts include OLE file writes (OleFileWritten events) creating .dll or .exe files containing 'WindowsPowerShell\v1.0\' in the path, DLL writes by Falcon's remediation process into protected system directories, and suspicious SYSTEM-level process creation (Windows Event 4688) immediately following Falcon remediation events. The researcher also noted an artifact path of C:\Windows\System32\MY_SNAKE_IS_SOLID.dll reportedly created with user-controllable permissions upon execution.

MITIGATION: CrowdStrike confirmed they are 'actively investigating' and published a FalconFlank Tech Alert on their customer support portal. Their advised interim mitigation is to disable the 'Microsoft Office File Suspicious Macro Removal' Windows policy setting in the CrowdStrike Falcon console (Next-gen antivirus settings > Clean infected Microsoft Office files). The Cloud Anti-malware for Microsoft Office Files settings remain active and continue to provide protection against malicious macros even with the problematic remediation policy disabled. No code-level patch has been released as of September 6.

CONTEXT: FalconFlank is the third endpoint-security zero-day from this researcher in approximately five weeks, following HardBreacher (Kaspersky Endpoint Security, resolved via auto-update) and ShieldBreak / CVE-2026-69414 (Microsoft Defender, a full bypass of the earlier RoguePlanet patch). A recurring pattern across these exploits is that each weaponizes a security product's own remediation or privileged code path as the escalation primitive — a 'trusted-binary-abuse' class that resists traditional application allowlisting since the parent process is the legitimate security agent itself. The same researcher has been in conflict with Microsoft, who threatened legal action after the researcher began publishing zero-days against their products following frustration with Microsoft's bug bounty and vulnerability handling process. Kevin Beaumont independently confirmed FalconFlank is real and functional.

RISK ASSESSMENT: While no in-the-wild exploitation by APT groups or cybercriminal actors has been confirmed as of this writing, the public availability of a working PoC for a vulnerability in the most widely deployed EDR product in enterprise environments makes weaponization by threat actors highly probable. The exploit is especially dangerous because achieving SYSTEM privileges via Falcon's own code path allows an attacker to then disable or tamper with the very security sensor protecting the endpoint, by modifying Falcon's exclusions, policies, or agent configuration. This creates a compound risk: the defense mechanism itself becomes the attack vector.

## MITRE ATT&CK

- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1548 Abuse Elevation Control Mechanism
- T1685 Disable or Modify Tools
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1003 OS Credential Dumping
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1082 System Information Discovery
- T1057 Process Discovery
- T1012 Query Registry
- T1112 Modify Registry
- T1106 Native API

## Sources

- [New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/)
- [Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon](https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html)
- [FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor](https://databreaches.net/2026/09/05/falconflank-zero-day-hits-crowdstrike-falcon-sensor/)
- [Detection Guidance for FalconFlank](https://www.abstract.security/blog/chaotic-eclipse-releases-crowdstrike-falcon-zero-day-falconflank-detection-guidance)
- [FalconFlank Technical Analysis](https://www.rescana.com/post/falconflank-zero-day-exposes-critical-privilege-escalation-vulnerability-in-crowdstrike-falcon-sensor-for-windows-11-and)
- [FalconFlank: CrowdStrike Falcon Sensor LPE Threat Advisory](https://blackswan-cybersecurity.com/threat-advisory-crowdstrike-falcon-sensor-local-privilege-escalation-zero-day-falconflank-august-26-2026/)
- [Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC](https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/)
- [FalconFlank — CrowdStrike Falcon Sensor LPE (threat.wiki)](https://threat.wiki/ops/falconflank-crowdstrike-falcon-privilege-escalation-chaotic-eclipse-september-2026/)
- [CrowdStrike FalconFlank Tech Alert (Customer Support Portal)](https://supportportal.crowdstrike.com/)
- [Kevin Beaumont Confirms FalconFlank (LinkedIn)](https://www.linkedin.com/posts/kevin-beaumont-security_prolific-microsoft-0-day-hunter-drops-crowdstrike-activity-7501385036001091585-o-QI)
- [FalconFlank PoC Repository (Project NightCrawler)](https://git.projectnightcrawler.dev/NightmareEclipse/FalconFlank)
- [CrowdStrike's FalconFlank Zero-Day Allows SYSTEM Privileges](https://infosecbulletin.com/crowdstrikes-falconflank-zero-day-allows-system-privileges/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2362
