An anonymous security researcher known as “Nightmare Eclipse” has released a CrowdStrike Falcon zero-day exploit called FalconFlank. The exploit reportedly enables privilege escalation on modern Windows systems.
The vulnerability has not yet been assigned a CVE identifier. According to Nightmare Eclipse, it affects fully updated versions of Windows 11 and Windows Server, as well as systems running CrowdStrike’s Falcon endpoint security platform.
If successfully exploited, the vulnerability could allow an attacker to abuse CrowdStrike Falcon’s Microsoft Office malicious macro repair feature to launch a command prompt with SYSTEM-level privileges.
“FalconFlank is a zero-day privilege escalation that exploits malicious macro repair in the CrowdStrike Falcon Sensor’s Office protection,” Nightmare Eclipse said. The researcher claimed that the exploit works on fully updated Windows 11 25H2, Windows Server 2025, and CrowdStrike Falcon installations.
When BleepingComputer asked CrowdStrike for more information, the company said it was investigating the claims. CrowdStrike also advised customers to disable the Microsoft Office Windows policy setting that allows the security software to remove suspicious macros from files.
A CrowdStrike spokesperson told BleepingComputer: “We are actively investigating these allegations and are advising customers to disable the Remove Suspicious Macros in Microsoft Office Files Windows policy setting.” The company added that customers remain protected through its anti-cloud malware settings for Microsoft Office files and directed them to the FalconFlank technical alert on the CrowdStrike Support Portal.
The CrowdStrike FalconFlank technical alert is not publicly available. Access is limited to customers with an account on the company’s support portal.
Nightmare Eclipse has also released several other security research projects this week, including HardBreacher, which targets Kaspersky Antivirus for Endpoint; Pretty Prague, which targets Gen Digital’s Avast Antivirus; and Green Section, a denial-of-service vulnerability affecting Nvidia software.
Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploit released by Nightmare Eclipse is genuine and works as described.
Since April, Nightmare Eclipse has also claimed to have discovered multiple zero-day vulnerabilities affecting Microsoft products, including Microsoft Defender, BitLocker, and other Windows components.
The reported Microsoft vulnerabilities include LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and Remove Defense. Microsoft has since fixed the LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma vulnerabilities. Other reported flaws remain unpatched and are still considered zero-day vulnerabilities.
After Nightmare Eclipse disclosed the first vulnerability, Microsoft responded publicly and issued a warning about potential legal action. The company said it may pursue individuals involved in malicious activities that cause real harm to customers, prompting concerns among some security researchers about the implications for vulnerability disclosures.
The overall prevention score can obscure what happens after initial access. If an attacker uses valid credentials, security defenses can become significantly less effective.
The Blue Report 2026 measures defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



