Public FalconFlank zero-day in CrowdStrike Falcon Sensor can give attackers SYSTEM access on Windows

A newly disclosed CrowdStrike Falcon Sensor flaw can let an attacker who already has code running on a Windows machine gain full SYSTEM privileges. The zero-day, dubbed FalconFlank, abuses CrowdStrike’s Microsoft Office suspicious macro removal workflow through a time-of-check to time-of-use race condition to trigger DLL side-loading as NT AUTHORITY\SYSTEM. It reportedly affects fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon in Phase 3 Optimal Protection with the macro removal policy enabled. A public proof of concept is available, and CrowdStrike had not yet issued a public patch at the time of the report.
Why it matters: Organizations using CrowdStrike Falcon on Windows should treat this as urgent because a local foothold could be turned into full machine takeover. The immediate action is to disable the affected Falcon macro-removal policy and apply Office macro restrictions while waiting for vendor fixes or an advisory.

Sources

CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day (FalconFlank)
Arctic Wolf Labs 2026.09.04 100% relevant
This article appears to be the first item here establishing FalconFlank as a distinct CrowdStrike Falcon Sensor zero-day event, including the exploit details, affected configuration, public PoC status, and interim workaround.
← Back to all stories