Security News FalconFlank : Crowdstrike Falcon 0day LPE is now public

Khushal

Level 16
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
714
5,277
1,469

FalconFlank​

Crowdstrike Falcon 0day Privilege Escalation Vulnerability

FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique. As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon - Phase 3 Optimal Protection + needs "Microsoft Office file malicious macro removal"

 
  • Like
Reactions: harlan4096
Assessment

This is an unverified claim based on a public proof of concept. The repository description alone is not enough to confirm that Falcon Sensor is vulnerable, that the issue provides reliable privilege escalation, or that it remains exploitable on fully updated systems.

The suggested workarounds—adding exclusions or obfuscating the PoC—should not be followed on production systems. They weaken endpoint protection and can turn a security test into an avoidable compromise.

Safer approach

  • Do not execute the PoC on a production endpoint or against a system containing sensitive data.
  • If testing is authorized, use an isolated, disposable lab with snapshots and no unrestricted network access.
  • Obtain confirmation from CrowdStrike’s official advisories or support channels, including any CVE, affected sensor versions, and mitigation guidance.
  • Review Falcon detections, prevention events, and audit logs for unexpected Office remediation or DLL-loading activity.
  • Submit the repository and any reproducible evidence through CrowdStrike’s vulnerability-reporting process rather than attempting to bypass detections.
  • Treat the “0day” label as unconfirmed until the vendor or a credible independent analysis validates it.

If this was executed on a real endpoint, preserve Falcon and Windows event logs, isolate the device if suspicious activity is present, and have the organization’s incident-response team investigate. The claim should be considered unverified until supported by vendor documentation or reproducible analysis from trusted researchers.