Security2 distinct publishers3 min readPublished
Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The privilege in this class of bug comes from the cleanup step. Falcon's Microsoft Office malicious macro removal sits inside the sensor's remediation set and operates with high privileges, and the researcher's claim, per Security Affairs, is that a low-privileged local user can ride that behaviour into a stronger context [3].
What is published is thin. The README names the feature, the platform, and the policy state: Phase 3 Optimal Protection with macro removal switched on [2][4]. For the anatomy of the class, the documented case is the same researcher's Defender bug. LevelBlue described ShieldBreak as Cloud Files, Object Manager namespace manipulation, direct Defender API calls and a timing race in the remediation path, ending with Defender's own clean engine writing an attacker DLL to System32 and SYSTEM execution through the built-in Windows Error Reporting task [12]. Earlier chains from the same researcher, RedSun and LegacyHive, reached the same destination by other routes [19].
The tally now stands at four endpoint products with public exploit code from one person: CrowdStrike, Kaspersky, Microsoft, and Gen Digital's Avast [16]. Two of the four chains go through vendor cleanup code [18]. On vendor position the tally is one fix on record. Kaspersky says HardBreacher is resolved [10]. Microsoft has shipped nothing for ShieldBreak, which is assessed as a bypass of the CVE-2026-50656 patch [11]. CrowdStrike had not responded to The Hacker News, and the reporting carries no Gen Digital response [7][17].
The researcher expects Falcon to flag the published code, and tells anyone testing to add an exclusion or obfuscate the PoC and change the DLL load technique [5]. That is the bind: validating the sensor with the public code requires degrading the sensor first. Security Affairs adds the accompanying caution, that a detection on this PoC leaves open whether the underlying path is closed [6]. Kaspersky's own remedy arrived by automatic update or a manually triggered database update, the channel detection content ships on; the source does not say what changed inside the product [10].
Absent a CrowdStrike statement, the telemetry is yours to assemble, and it is telemetry most shops do not collect about their own agent. That means watching for DLL creation in System32 attributed to sensor-privileged processes, for changes to the macro removal setting in policy, and for execution of the Windows Error Reporting task that the Defender chain used for its final step [12].
Timing is stated rather than guessed. In a post dated 14 August 2026 the researcher said Microsoft refuses to communicate and floated publishing third-party bugs in the window before Patch Tuesday [14]. Security Affairs notes that some earlier releases were later exploited in the wild [15]. Plan around the gap between a drop and a content update, because there is no tracking number to wait for: only the Defender bugs in this set carry CVEs [20].
Ranked by verification strength, evidence, and original report placement.
Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a zero-day privilege escalation exploit named FalconFlank targeting CrowdStrike Falcon.
The researcher's GitHub README states: "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor."
FalconFlank abuses Falcon's "Microsoft Office file malicious macro removal" feature, which is part of Falcon's remediation capabilities and operates with high privileges; the researcher claims the behaviour can be abused to escalate from a low-privileged local user to a more powerful context.
The Hacker News said it had contacted CrowdStrike for comment and would update the story if it heard back.
The PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 Optimal Protection and the Microsoft Office file malicious macro removal feature enabled.
The researcher said CrowdStrike would likely already have detections for the PoC by release, so testers must either add it to exclusions or obfuscate the PoC and change the DLL load technique.
Follow any of these and your For You feed starts watching them — no settings page required.
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
build
A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply1 distinct publisher
security
Two years, 117 identified children: the only Com case this week with an outcome attached1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One README, two retellings
Every technical assertion about FalconFlank in this story descends from the researcher's own GitHub announcement. The Hacker News quotes it; Security Affairs quotes it more fully and adds the protection tier and feature prerequisite. Neither ran the code, no CVE exists, and CrowdStrike has not confirmed, disputed or scoped anything. Independent voices appear only around the neighbouring bugs — LevelBlue on the Defender chain, Kaspersky on its own fix — which is corroboration for the pattern, not for this exploit.
Code is public, victims are not
What is demonstrably in the world is exploit code: four endpoint products in a matter of weeks, downloadable, with the Kaspersky one reportedly leaving the whole machine unstable. What is not in the world, as far as this reporting shows, is a single FalconFlank intrusion, a Falcon detection statistic, or an affected-customer count. The nearest thing to real-world uptake is historical — Security Affairs' note that Undefend and RedSun ended up being used in attacks — and the only vendor-side motion anyone recorded is Kaspersky pushing a database update.
Zero-day with an asterisk
The framing runs slightly ahead of what has been shown. A researcher who tells you to add his exploit to your exclusions before it will run has conceded that the shipped artifact is, as shipped, blocked — and that caveat sits below the headline in both accounts rather than in it. The overstatement is modest rather than large because Security Affairs makes the honest counterpoint that a signature is not a patch, and because the code itself is real and available. What no one can currently say is whether the underlying weakness in Falcon's macro cleanup survives obfuscation, which is precisely the question the headline implies is settled.
Disclosure used as leverage
The motives here are stated out loud, which makes them easy to weigh. The researcher says Microsoft refuses to talk, that its restrictions block him from reporting to other vendors, and that he is minded to publish third-party bugs in the gap before Patch Tuesday — release timing chosen for maximum pressure, not maximum safety. On the other side, the single vendor quote in this coverage is a reassurance ('resolved', 'automatic update') from a company with an obvious interest in closing the item, delivered through the outlet that asked. And a security publication reporting a working exploit against the best-known EDR brand is not a neutral editorial choice either.
Solid on the what, blank on the so-what
Who published what, when, against which product and under which conditions is firm and duplicated across both outlets. Everything a defender would actually decide on is open: whether the flaw exists independently of the blocked technique, which sensor builds are affected, whether anyone is using it, and what CrowdStrike intends to do. Note too that the two Hacker News filings are the same piece at different moments, so the apparent volume of coverage is thinner than it looks.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
2 articles · September 3, 2026