FalconFlank turns a standard Windows user into SYSTEM through CrowdStrike remediation.
The complete exploit is public and independently reproduced, and no patch is available.
Affects
CrowdStrike Falcon Sensor deployments on Windows endpoints using the Microsoft Office suspicious-macro-removal prevention policy.
What it enables
Local privilege escalation from a standard user to SYSTEM
Run the public FalconFlank program as a standard Windows user.→↓Stage an attacker DLL beneath a lookalike WindowsPowerShell path and coordinate the remediation race with an oplock.→↓Replace the staged directory with a junction to the real System32 PowerShell directory and use the transacted-file path to overwrite bcrypt.dll.→↓Wait for Falcon's MareBackup scheduled task, running as SYSTEM, to load the substituted DLL.→↓Use the payload's named-pipe channel to execute commands as SYSTEM.
Why this matters
The change is a working escalation through the endpoint-defense workflow trusted to remediate hostile Office content, not merely another local race.
Detail, proof-of-concept code and 4 sources
Required access
Local unprivileged code execution on a Windows endpoint where Falcon's Microsoft Office File Suspicious Macro Removal policy is enabled
Affected versions
Current Windows 11 25H2 and Windows Server 2025 systems were reported affected; the public material does not identify an exact Falcon Sensor build range.
With Microsoft Office File Suspicious Macro Removal enabled, an unprivileged user can use junction, oplock and transacted-file races to redirect Falcon's privileged filesystem work into the protected PowerShell bcrypt.dll path.
The MareBackup scheduled task later loads the substituted DLL as SYSTEM, and the payload's named pipe accepts commands.
CrowdStrike acknowledged the investigation and recommends disabling the implicated prevention policy while keeping its other protection enabled; no patch was available at cutoff.
Evidence
The public repository and C++ source implement the complete standard-user-to-SYSTEM chain.Vega reports independent laboratory reproduction of SYSTEM command execution.CrowdStrike's public response acknowledged investigation and recommended disabling the implicated prevention policy while leaving other protection enabled.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.