A public zero-day turns CrowdStrike Falcon into an admin key

Security software designed to stop attackers can now be abused to gain local administrator rights.
Security researcher MSNightmare published FalconFlank, a zero-day exploit targeting the CrowdStrike Falcon Sensor. The proof-of-concept abuses the agent's malicious macro remediation feature to escalate privileges on fully updated Windows 11 25H2 and Windows Server 2025 machines running Phase 3 Optimal Protection. The repository picked up over 500 GitHub stars this week.
Why it matters: Security agents run with deep system access, turning any flaw in their remediation code into a high-value target. An attacker with basic access on a machine can use the endpoint agent itself to take full local control.
Know this: CrowdStrike likely has detections active for the unedited exploit payload. Testers looking to verify the bug in a lab will need to add exclusions or modify the payload's DLL loading technique.
Endpoint security tools remain the most trusted software on the machine—until they aren't.
Sources
- MSNightmare/FalconFlank — https://github.com/MSNightmare/FalconFlank

