Skip to main content
CrowdStrikeSecurity incident

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

What happened

A security researcher disclosed a zero-day privilege escalation vulnerability, named FalconFlank, in CrowdStrike's Falcon endpoint security platform, which abuses the Microsoft Office malicious macros remediation feature.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Security A shared security 'Nightmare' The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike's Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting," a CrowdStrike spokesperson told The Register. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike...

Keep reading with a free account

The rest of this article, and every signal for CrowdStrike, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
Falcon
Issue
FalconFlank privilege escalation vulnerability
Takes effect
Sep 3, 2026

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
FalconFlank privilege escalation vulnerability

Topics and mentions

Product tags

  • security
  • general technology

Extraction

Confidence
90%
Detected
Sep 3, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for CrowdStrike and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at CrowdStrike this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/6b926447-8787-afeb-7a8e-de6951fe5629 returns this record as JSON. POST /v1/companies/enrich returns every signal for crowdstrike.com.

{
  "signal_id": "6b926447-8787-afeb-7a8e-de6951fe5629",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-03T18:08:22+00:00",
  "company": {
    "name": "CrowdStrike",
    "domain": "crowdstrike.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318",
    "title": "Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC",
    "excerpt": "Security A shared security 'Nightmare' The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter , FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register . “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike...",
    "product": "Falcon",
    "summary": "A security researcher disclosed a zero-day privilege escalation vulnerability, named FalconFlank, in CrowdStrike's Falcon endpoint security platform, which abuses the Microsoft Office malicious macros remediation feature.",
    "planning": false,
    "image_url": "https://image.theregister.com/5294333.jpg?imageId=5294333&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "product_data": {
      "name": "Falcon",
      "full_text": "CrowdStrike’s Falcon endpoint security platform",
      "fuzzy_match": false
    },
    "product_tags": [
      "security",
      "general_technology"
    ],
    "published_at": "2026-09-03T18:08:22Z",
    "vulnerability": "FalconFlank privilege escalation vulnerability",
    "effective_date": "2026-09-03",
    "article_sentence": "On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link.",
    "related_company_name": "Microsoft",
    "related_company_domain": "microsoft.com"
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.