Abstract ASTRO Research Blog Offers Way to Detect CrowdStrike Falcon Zero-Day FalconFlank Highlighted by Chaotic Eclipse Researcher

As you probably have already seen, a security researcher known as Chaotic Eclipse has published a proof-of-concept exploit called FalconFlank targeting CrowdStrike’s Falcon endpoint platform — the latest in a pattern of public releases against major endpoint security products, following recent disclosures against Kaspersky Endpoint Security and Gen Digital’s Avast Antivirus.

Abstract’s ASTRO research team blogged about it this afternoon and here are some highlights:

  • The exploit turns Falcon’s own defenses against it. FalconFlank reportedly abuses Falcon’s Microsoft Office malicious-macro-removal feature. It’s a remediation function that runs with elevated privileges and escalates from a low-privileged local user to a more powerful context on fully patched Windows 11 25H2 and Windows Server 2025 systems.
  • No CVE, no vendor confirmation yet. As of the blog’s publication, CrowdStrike has not confirmed the flaw’s validity or scope, and there’s no assigned CVE. The technical claims are researcher-provided and currently unverified.
  • A track record worth noting. This researcher has previously released working exploits, largely against Microsoft products including Windows and Defender, with some later observed being abused in the wild…often following public criticism of vendor vulnerability-handling processes.
  • Defenders aren’t stuck waiting on a patch. Abstract ASTRO has published behavioral detection logic, keyed on the underlying mechanism (an anomalous OLE file write, a specific DLL artifact, and a directory-mirroring/coordination pattern) rather than the exact published sample, which means it should hold up even against evasion attempts the researcher has already flagged.

Abstract points out that it’s tricky wth EDR products: the privileges these agents need to protect a host are the same privileges that create new attack surface when abused.

UPDATE: A CrowdStrike spokesperson said:

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading