Skip to finding
§
High
Privilege — Windows
Confirmed

FalconFlank turns a standard Windows user into SYSTEM through CrowdStrike remediation.

The complete exploit is public and independently reproduced, and no patch is available.

Affects

CrowdStrike Falcon Sensor deployments on Windows endpoints using the Microsoft Office suspicious-macro-removal prevention policy.

What it enables

Local privilege escalation from a standard user to SYSTEM

Run the public FalconFlank program as a standard Windows user.→↓Stage an attacker DLL beneath a lookalike WindowsPowerShell path and coordinate the remediation race with an oplock.→↓Replace the staged directory with a junction to the real System32 PowerShell directory and use the transacted-file path to overwrite bcrypt.dll.→↓Wait for Falcon's MareBackup scheduled task, running as SYSTEM, to load the substituted DLL.→↓Use the payload's named-pipe channel to execute commands as SYSTEM.
Why this matters

The change is a working escalation through the endpoint-defense workflow trusted to remediate hostile Office content, not merely another local race.

Detail, proof-of-concept code and 4 sources
Required access

Local unprivileged code execution on a Windows endpoint where Falcon's Microsoft Office File Suspicious Macro Removal policy is enabled

Affected versions

Current Windows 11 25H2 and Windows Server 2025 systems were reported affected; the public material does not identify an exact Falcon Sensor build range.

Proof of concept

Public exploit code →

With Microsoft Office File Suspicious Macro Removal enabled, an unprivileged user can use junction, oplock and transacted-file races to redirect Falcon's privileged filesystem work into the protected PowerShell bcrypt.dll path.

The MareBackup scheduled task later loads the substituted DLL as SYSTEM, and the payload's named pipe accepts commands.

CrowdStrike acknowledged the investigation and recommends disabling the implicated prevention policy while keeping its other protection enabled; no patch was available at cutoff.

Evidence
The public repository and C++ source implement the complete standard-user-to-SYSTEM chain.Vega reports independent laboratory reproduction of SYSTEM command execution.CrowdStrike's public response acknowledged investigation and recommended disabling the implicated prevention policy while leaving other protection enabled.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026