type: incident ยท created: 2026-09-05 ยท updated: 2026-09-05 ยท tags: [incident, zero-day, privilege-escalation, crowdstrike, edr] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true
CrowdStrike Falcon 'FalconFlank' Zero-Day Escalates to SYSTEM
An anonymous researcher using the handle "Nightmare Eclipse" released a zero-day privilege-escalation exploit named "FalconFlank" targeting CrowdStrike Falcon, which lets attackers spawn a SYSTEM command prompt on up-to-date Windows 11 (25H2) and Windows Server 2025 systems by abusing the endpoint software's own mechanisms.
| Attribute | Detail |
|---|---|
| Researcher | Nightmare Eclipse (anonymous) |
| Exploit | FalconFlank |
| Target | CrowdStrike Falcon (EDR) |
| Impact | SYSTEM spawn on fully-patched Windows 11 25H2 / Server 2025 |
| Source | BleepingComputer โ Tier 2/4 |
An EDR local-privilege-escalation zero-day against fully-patched systems โ notable because it exploits the security tool itself, undermining the very layer organisations rely on. Australian and NZ defenders should treat EDR-supplier LPE claims as high-priority patching, not hypothetical.