Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Researcher Nightmare Eclipse unveils CrowdStrike Falcon privilege-escalation zero-day

A hacker known as Nightmare Eclipse released a proof-of-concept for FalconFlank, a zero-day that escalates privileges via CrowdStrike Falcon’s Microsoft Office macro removal feature on fully patched Windows 11 and Server systems.

Nightmare Eclipse, a prolific zero-day author, published a proof-of-concept called FalconFlank that leverages the Microsoft Office malicious-macro remediation component built into CrowdStrike Falcon. The vulnerability grants system-level privileges on fully updated Windows 11 25H2 and Windows Server 2025 hosts running the Falcon platform with Phase 3 - Optimal Protection and the macro-removal policy enabled. CrowdStrike responded by urging customers to turn off the “Microsoft Office File Suspicious Macro Removal Windows” setting and directed them to its Cloud Anti-malware for Office files for continued protection.

Kevin Beaumont verified the exploit and observed that the researcher is expanding attacks to other endpoint products, having recently disclosed HardBreacher in Kaspersky and PrettyPrague in Avast, as well as a non-functional Nvidia memory-corruption flaw. These disclosures underscore persistent weaknesses in endpoint security solutions and pressure vendors to improve hardening.

Why it matters

The flaw could let attackers gain full system control on machines protected by CrowdStrike, exposing many organizations to serious breaches.

In this story

zero-dayprivilege escalationFalconFlankCrowdStrike FalconMicrosoft Office macro removalWindows 11security researcherendpoint securityexploit proof-of-concept
Get the beta ↗