FalconFlank PoC Exposes CrowdStrike Privilege Escalation
A researcher released a proof-of-concept exploit for a privilege escalation flaw in CrowdStrike Falcon, dubbed FalconFlank, which abuses the sensor's macro

A security researcher known as Chaotic Eclipse has published a proof-of-concept exploit for a new privilege escalation vulnerability in CrowdStrike's Falcon endpoint sensor. The flaw, named FalconFlank, abuses the software's office malicious macro remediation feature, according to the GitHub README file.
CrowdStrike may already have detections for the flaw. To test the exploit, one would need to add it to exclusions or obfuscate the PoC and change the DLL load technique. The Hacker News reported contacting CrowdStrike for comment but had not received a response at the time of publication.
Exploit Details and Requirements
The FalconFlank proof-of-concept works on a fully updated Windows 11 25H2 machine or Windows Server 2025 with CrowdStrike Falcon installed. It was described as a zero-day privilege escalation vulnerability.
Recent Activity by Chaotic Eclipse
The new release comes after the same individual published a PoC for another privilege escalation flaw, this time impacting Kaspersky's endpoint security product for Windows, version 14.0.0.504. That exploit was codenamed HardBreacher.
The HardBreacher PoC was characterized as being in poor shape, described as basically duct taped. It was noted to often fail to run with an error and require repeated attempts. If successful, it creates a file named C:WindowsSystem32MY_SNAKE_IS_SOLID.dll with full permissions for the current user.
Chaotic Eclipse claimed the interesting part is that Kaspersky completely loses it when you take control over the UI process. The exploit could cause the software to stop functioning and grant or block access to files it should not, creating a hot mess for the entire operating system if successful.
Previous Microsoft Defender Exploit
In the prior month, a proof-of-concept for a Microsoft Defender zero-day called ShieldBreak, also known as CVE-2026-69414, was published. This flaw could allow an attacker to run arbitrary code with SYSTEM privileges. Security firm LevelBlue assessed it as a patch bypass for an earlier vulnerability, CVE-2026-50656, known as RoguePlanet. Microsoft has not yet released a fix.
LevelBlue provided analysis, stating that like its predecessors, ShieldBreak explores a different corner of the Windows operating system. They explained that where previous exploits abused specific APIs and services, ShieldBreak combines Cloud Files, Object Manager namespace manipulation, direct Windows Defender API invocation, and a timing race in the remediation path.
The result is a local privilege escalation chain where Windows Defender's clean engine is redirected to write an attacker-supplied DLL to C:Windows\System32phoneinfo.dll, followed by SYSTEM execution via the built-in Windows Error Reporting task.
Grievances with Microsoft
Following the ShieldBreak disclosure, Chaotic Eclipse claimed that Microsoft continues to ignore them and refuses any communication. They accused the company of trying to portray them as some insane criminal.
In an August 14, 2026 post, the individual expressed frustration, stating they can't even report the bugs they find to their respective vendors because of the restrictions by Microsoft, all of this is of their own doing. They lamented that Microsoft does not bother to check their case to understand the problem.
A new approach was suggested, saying they might start publishing bugs for third-parties in that window where patch Tuesday isn't released yet. They concluded with a personal plea, asking if wanting to live like a normal human being for once in life was too much to ask for.





