CrowdStrike customers have an immediate configuration change to make while the company investigates FalconFlank, a public proof-of-concept that reportedly allows a low-privilege Windows user to gain SYSTEM-level access on a Falcon-protected endpoint.
CrowdStrike has advised customers to disable the Microsoft Office File Malicious Macro Removal setting. A September 4 update to its customer Tech Alert says the company also deployed behavioral protections against key stages of the attack chain and continues hunting for signs of exploitation.
The FalconFlank proof-of-concept was published September 3, 2026. No CVE had been publicly assigned as of September 7, and CrowdStrike had not disclosed confirmed exploitation in real-world attacks. Independent security firm Vega has reproduced the privilege escalation in a controlled lab.
FalconFlank turns local access into SYSTEM privileges
FalconFlank is a local privilege-escalation technique, not an initial-access exploit. An attacker must already be able to run code as a low-privilege Windows user before attempting to elevate privileges. The disclosure follows the recent ShieldBreak Windows Defender flaw, which also exposed a route from local access to SYSTEM privileges.
CrowdStrike advised customers to disable the affected Office macro-removal setting while its investigation continues. The company says customers whose prevention policies follow its best practices remain protected against malicious Office files through Cloud Anti-malware for Microsoft Office Files.
The researcher says the PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems running Falcon with Phase 3 — Optimal Protection and the macro-removal feature enabled. CrowdStrike has not confirmed that as a complete list of affected systems or identified a fixed Falcon Sensor version.
Vega reproduced the exploit by staging a malicious bcrypt.dll in a user-controlled location and using filesystem redirection and Transacted NTFS to target a protected PowerShell directory. The Falcon-installed MareBackup scheduled task then runs as SYSTEM and loads the tampered DLL, allowing attacker-controlled code to execute with SYSTEM privileges.
Vega reported that the final overwrite did not appear in Falcon telemetry during its test. Modern endpoint detection and response tools can correlate behavior across the attack chain, which is more reliable than relying only on filenames or other PoC artifacts that attackers can easily change.
CrowdStrike mitigation leads the response
Organizations should apply CrowdStrike’s configuration change first, then strengthen hunting, endpoint controls, and response readiness around the remaining risk.
- Disable the affected macro-removal setting. Turn off Microsoft Office File Malicious Macro Removal as directed by CrowdStrike.
- Confirm remaining Office protections are active. Ensure prevention policies follow CrowdStrike best practices and Cloud Anti-malware for Microsoft Office Files remains enabled.
- Hunt for attack-chain behavior. Monitor suspicious DLL staging, abnormal
bcrypt.dllactivity, named pipes, filesystem redirection, and unexpected MareBackup execution.
- Correlate MareBackup with earlier file activity. Investigate execution that follows unusual DLL writes or filesystem changes on the same endpoint.
- Limit low-privilege code execution. Apply least privilege and application control, and restrict execution from user-writable locations where practical.
- Test incident response plans. Confirm teams can detect, isolate, and investigate attempted privilege escalation and retain the Windows and Falcon telemetry needed for analysis.
- Monitor CrowdStrike guidance. Track the FalconFlank Tech Alert for new detections, affected versions, remediation guidance, or a fixed Falcon Sensor release.
CrowdStrike’s 2026 threat-hunting report found that 88% of observed vulnerability attacks began within 48 hours of public PoC release, adding urgency to mitigation and behavioral hunting while FalconFlank remains under investigation.
Until CrowdStrike publishes a definitive fix or updated affected-system scope, the priority is to remove the reported prerequisite, watch for the demonstrated attack-chain behavior, and be prepared to contain privilege escalation quickly.
Read more: Microsoft’s recent August security updates also addressed an actively exploited Windows flaw that could elevate a low-privilege attacker to SYSTEM.





