Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

The recent actions of the security researcher known as Nightmare Eclipse, who has previously focused on vulnerabilities within Microsoft products, have taken a notable turn. This individual, also referred to as Chaotic Eclipse and Infinite Nightmare, has now shifted their attention to other vendors, unveiling a new zero-day vulnerability dubbed FalconFlank. This particular flaw targets CrowdStrike’s Falcon endpoint security platform, establishing a connection to Windows systems.

Details of the Vulnerability

Nightmare Eclipse describes FalconFlank as a privilege escalation vulnerability that exploits the Microsoft Office malicious macros remediation feature integrated within CrowdStrike Falcon. This automated security tool is designed to scrutinize Microsoft Office documents for potentially harmful macros, stripping away any suspect code to prevent the execution of malicious payloads when users open the documents.

A spokesperson from CrowdStrike responded to the discovery, stating, “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.” They assured customers that protection remains intact through the Cloud Anti-malware for Microsoft Office Files settings and directed them to the FalconFlank Tech Alert available in the CrowdStrike support portal.

The proof-of-concept (PoC) exploit is said to function on fully updated Windows 11 25H2 and Windows Server 2025 systems that are running CrowdStrike Falcon with Phase 3 – Optimal Protection enabled. Nightmare Eclipse noted in a GitHub README that testing the exploit would require either adding it to exclusions or obfuscating the PoC to alter the DLL load technique, as CrowdStrike would likely have detections in place by the time of the release.

Industry Reactions

Security expert Kevin Beaumont has confirmed the functionality of this exploit, along with several others released by Nightmare in recent days. Beaumont expressed that it is not surprising to see Nightmare exploring vulnerabilities beyond Microsoft, stating, “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products.” He emphasized the hope that this scrutiny would prompt cybersecurity vendors to enhance their offerings and focus on securing their products rather than hyping hypothetical threats.

FalconFlank is not an isolated incident; it follows a series of vulnerabilities discovered by Nightmare in various endpoint and antivirus products. Among these is HardBreacher, an elevation of privilege bug affecting Kaspersky’s endpoint antivirus solution. Nightmare indicated that the issue is now extending beyond Microsoft, having conducted a poll that favored finding a bug in the commercial version of Kaspersky’s product. Beaumont has confirmed the effectiveness of Nightmare’s HardBreacher exploit code, as well as a PoC for an elevation of privileges vulnerability in Gen Digital’s Avast antivirus software, named PrettyPrague. This particular zero-day is reported to allow attackers to dump the SAM database by exploiting a flaw in Avast Sandbox.

In response to the discovery of the vulnerability, Gen Digital stated, “We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly.” Meanwhile, Kaspersky has yet to provide a comment on the matter.

Additionally, Nightmare has recently disclosed an Nvidia memory corruption zero-day vulnerability known as GreenSection, although Beaumont noted that this particular flaw merely causes system crashes. Nvidia has not responded to inquiries regarding this vulnerability.

Tech Optimizer
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC