Ethical Hacking News
Chaotic Eclipse has released a new zero-day vulnerability, FalconFlank, which puts CrowdStrike Falcon and Windows systems at risk. This privilege escalation flaw can be exploited by attackers to gain control over the UI process and potentially bring the entire operating system to a halt.
CrowdStrike Falcon is vulnerable to the FalconFlank zero-day exploit, which targets the office malicious macros remediation feature.The vulnerability affects Windows 11 25H2 machines and Windows Server 2025 with Crowdstrike Falcon.A Kaspersky endpoint security product version 14.0.0.504 is also affected by the exploit, allowing attackers to take control of the UI process.Chaotic Eclipse claims that Microsoft is not engaging with them, leading to a lack of transparency in cybersecurity.The vulnerability highlights the importance of keeping software up-to-date and remaining vigilant against emerging threats.
Chaotic Eclipse, a renowned security researcher, has made headlines once again by releasing a new zero-day vulnerability, dubbed FalconFlank. This privilege escalation flaw targets the office malicious macros remediation in CrowdStrike Falcon, a leading endpoint security solution. According to the researcher, CrowdStrike may already have detections for this flaw in place, suggesting that users are advised to either add exclusions or obfuscate the proof-of-concept (PoC) and modify the DLL load technique to avoid exploitation.
In a comprehensive analysis, Chaotic Eclipse revealed that the FalconFlank vulnerability exploits the Windows operating system, specifically in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon. The researcher emphasized that the PoC for this vulnerability is not in its most refined state, being described as "basically duct-taped" and prone to errors, which necessitates repeated runs to achieve success.
The implications of this vulnerability are significant, as Chaotic Eclipse pointed out that Kaspersky's endpoint security product for Windows, version 14.0.0.504, is also affected by this exploit. The researcher claimed that Kaspersky's response to this vulnerability is "completely losing it," allowing the attacker to take control of the UI process, block or grant access to files they shouldn't, and potentially bring the entire operating system to a grinding halt.
In the context of Chaotic Eclipse's prior work, this new vulnerability joins a growing list of exploits. The researcher had previously released PoCs for a Microsoft Defender zero-day, dubbed ShieldBreak, which was found to grant the attacker the ability to run arbitrary code with NT AUTHORITY\SYSTEM privileges. The researcher also published a PoC for a Microsoft Defender zero-day, codenamed RoguePlanet, which could be used as a patch bypass for CVE-2026-50656.
It is worth noting that Chaotic Eclipse has been vocal about Microsoft's alleged lack of engagement and cooperation. The researcher has claimed that Microsoft continues to "ghost" them and refuses to engage in any sort of communication, further emphasizing the need for transparency in cybersecurity.
This latest vulnerability highlights the ever-evolving threat landscape and the importance of keeping software up-to-date. As security experts continue to work towards creating more robust defenses, it is essential for users to remain vigilant and proactive in protecting themselves against emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Chaotic-Eclipse-Unleashes-New-Zero-Day-FalconFlank-Putting-CrowdStrike-Falcon-and-Windows-Systems-at-Risk-ehn.shtml
https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
https://cybersecuritynews.com/crowdstrike-falcon-0-day/
Published: Thu Sep 3 01:59:57 2026 by llama3.2 3B Q4_K_M