Chaotic Eclipse Unveils FalconFlank Zero-Day for Crowdstrike Falcon
Security researcher Chaotic Eclipse, also known by aliases like INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, has publicly released “FalconFlank,” a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability affecting the Crowdstrike Falcon cybersecurity platform.
Details of FalconFlank Exploit
FalconFlank exploits Falcon’s “Microsoft Office file malicious macro removal” feature. This remediation function, which operates with high privileges, can be abused to escalate privileges from a low-privileged local user to a more powerful system context.
The PoC has been confirmed to work on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with “Phase 3 – Optimal Protection” and the malicious macro removal feature enabled.
Chaotic Eclipse noted that CrowdStrike might already have detections for the published PoC, implying that while the specific exploit technique might be blocked, the underlying vulnerability could persist.
Broader Implications for EDR Security
This disclosure highlights a critical security challenge: Endpoint Detection and Response (EDR) products, by nature, require elevated privileges to effectively protect systems. However, these same elevated privileges can inadvertently become an attractive attack surface for adversaries who have gained initial low-level local access, allowing them to escalate their control over a system by targeting the security software itself.
Other Recent Exploits by Chaotic Eclipse
Chaotic Eclipse is known for targeting various anti-malware solutions. In addition to FalconFlank, the researcher has recently released PoCs for other zero-day vulnerabilities:
- HardBreacher (Kaspersky Endpoint Security): This exploit triggers a privilege escalation flaw in Kaspersky Endpoint Security v14.0.0.504 on fully patched Windows 11 25H2. It creates a DLL in System32 with full user permissions and can disrupt Kaspersky’s UI process, potentially leading to system instability.
- PrettyPrague (GenDigital Avast Antivirus): Targeting Avast Antivirus, this exploit abuses a flaw in the Avast Sandbox to dump the Windows SAM database and achieve a SYSTEM-level shell. It reportedly works on fully patched Avast Antivirus and Windows 11 25H2, and is suspected to affect other Gen Digital products such as AVG and Norton.
About Chaotic Eclipse
Chaotic Eclipse, or Nightmare Eclipse, has a history of publicly releasing PoC exploits for zero-day vulnerabilities. His disclosures often follow criticism of vendors’ handling of vulnerability reports. His previous targets have included Microsoft products, notably Windows and Microsoft Defender (e.g., Undefend and RedSun zero-days), some of which have later been exploited in the wild. His work consistently sparks debate within the cybersecurity community regarding the ethics and risks associated with public disclosure of working exploits.
Conclusión
The release of FalconFlank and other exploits by Chaotic Eclipse underscores the persistent challenge of securing critical security software. While EDR solutions are vital for defense, their privileged access introduces a potential attack vector that must be continuously addressed. The ongoing debate around responsible disclosure versus public release of PoCs also highlights the complex ethical considerations in vulnerability research.
Referencias
Original source: View original article