CrowdStrike Falcon Zero-Day PoC Enables SYSTEM Privilege Escalation on Windows
Security researchers have published a proof-of-concept exploit, dubbed FalconFlank, that abuses CrowdStrike Falcon Sensor's Microsoft Office macro removal feature to escalate privileges from a low-privileged user to SYSTEM on Windows endpoints. The PoC works by manipulating file operations during Falcon's macro remediation process to write a malicious DLL to a protected system path, specifically C:\Windows\System32\WindowsPowerShell\v1.0\bcrypt.dll, which is then loaded with elevated privileges. Exploitation requires the attacker to already have low-privileged local code execution on the target machine and the Falcon Sensor's Office macro removal setting to be active. No active in-the-wild attacks leveraging this technique have been observed as of the disclosure date of September 4, 2026. CrowdStrike has issued interim guidance recommending that administrators disable the Windows policy setting for Microsoft Office File Suspicious Macro Removal while a full fix is pending.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in