Privilege Escalation Vulnerability in Falcon Crowdstrike

FalconFlank abuses the office malicious macros remediation in Crowdstrike Falcon Sensor to achieve privilege escalation in the affected system.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Affected Products

As of now the PoC works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon – Phase 3 Optimal Protection with “Microsoft Office file malicious macro removal” setting.

Recommended Actions

It is advised to disable the “Microsoft Office File Suspicious Macro Removal Windows prevention” policy setting as soon as possible.

This setting can be found in the Next-gen antivirus settings under Clean infected Microsoft Office files.

After turning off the above feature, malicious macros will no longer be replaced. Customers with prevention policy settings configured, as per best practices, will remain protected. Prevention will continue to operate as normal via the Cloud Anti-malware for Microsoft Office Files settings.

References

[1] https://github.com/MSNightmare/FalconFlank

The post Privilege Escalation Vulnerability in Falcon Crowdstrike appeared first on Truesec.

Article Link: Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec