CrowdStrike is investigating a reported zero-day exploit in its Falcon endpoint security platform after an anonymous researcher using the handle “Nightmare Eclipse” released proof-of-concept code named “FalconFlank,” according to BleepingComputer. BleepingComputer reports that the exploit is said to allow privilege escalation on up-to-date Windows systems. The researcher claimed it works on fully updated Windows 11 25H2 and Windows Server 2025 machines running CrowdStrike Falcon. The reported impact is significant: successful exploitation can open a command prompt with SYSTEM privileges, according to BleepingComputer’s account of the release. SYSTEM is the high-privilege Windows context typically associated with core operating-system services, so a working escalation path from a security product is material for enterprise defenders. The claimed mechanism is specific. BleepingComputer reports that FalconFlank abuses CrowdStrike Falcon’s Office malicious macros remediation feature, which is designed to handle suspicious Microsoft Office macro content. The vulnerability has not yet been assigned a CVE identifier, according to the report. A company spokesperson told BleepingComputer that CrowdStrike is “actively investigating” the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. The provided BleepingComputer report does not include a patch confirmation or severity rating. CrowdStrike also told BleepingComputer that customers remain protected through Cloud Anti-malware for Microsoft Office Files settings, and pointed customers to a FalconFlank Tech Alert in the CrowdStrike support portal. BleepingComputer notes that the advisory is not public and is available only to customers with support-portal access. The FalconFlank disclosure is part of a broader run of releases from Nightmare Eclipse this week. BleepingComputer reports that the researcher also published privilege-escalation zero-days for Kaspersky Antivirus for Endpoint, named HardBreacher, and GenDigital Avast Antivirus, named PrettyPrague, along with a denial-of-service zero-day for Nvidia called GreenSection that crashes the system. Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege-escalation exploits released by Nightmare Eclipse this week are real and work, according to BleepingComputer. BleepingComputer’s report points to CrowdStrike’s investigation statement and the gated customer alert. Nightmare Eclipse has previously disclosed multiple zero-days affecting Microsoft products since April, BleepingComputer reports, including issues tied to Microsoft Defender, BitLocker, and other Windows components. Some of those reported Microsoft flaws have since been fixed, while others remain unpatched, according to the same report. Who benefits: Attackers who already have a path to trigger the exploit on an affected Windows system could benefit if the privilege-escalation claim holds. Defenders benefit from CrowdStrike’s interim mitigation guidance and customer tech alert. Who's exposed: Organizations running CrowdStrike Falcon on the Windows versions described in Nightmare Eclipse’s claim are the potentially exposed population described in the report. The provided material does not establish whether older Windows versions or other Falcon configurations are affected.