Chaotic Eclipse released FalconFlank, a proof of concept that shows local privilege escalation in CrowdStrike Falcon Sensor on fully updated Windows 11 25H2 and Windows Server 2025 systems. The issue is in Falcon's own malicious-macro remediation path, not in Windows itself.
The PoC abuses the security product's cleanup logic: Falcon tries to handle a malicious Office macro, and the attacker steers that trusted remediation work into privileged action. Because the flaw lives in the endpoint protection layer, patching the operating system alone does not remove the exposed path when Falcon Sensor is installed.
For teams that rely on auto-remediating endpoint security, the concern is the trust boundary inside the tool. If that cleanup path sits on your estate, the attack surface includes the control meant to contain the file or macro, and the reporting still does not show whether CrowdStrike already had detections when the PoC appeared.