VulnerabilityBleeping Computer
9.5 — CRITICAL
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A CrowdStrike zero-day exploit, 'FalconFlank', has been discovered that allows attackers to escalate privileges on up-to-date Windows systems by abusing the Office malicious macros remediation feature in Crowdstrike Falcon Sensor.
⚙️Technical Details
Affected Systems
Windows 11Windows Server
Attack Vectors
Office malicious macros remediation feature
💥Impact Assessment
Severity: critical
Who Is at Risk
Customers using up-to-date Windows systems with Crowdstrike Falcon Sensor
🛡️Recommended Actions
1Disable the Microsoft Office File Suspicious Macro Removal Windows policy setting
2Obfuscate or exclude the exploit from detection
3Apply a patch for the LegacyHive vulnerability
📦Affected Products
Crowdstrike Falcon SensorMicrosoft Office
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
