A public zero-day turns CrowdStrike Falcon into an admin key

A public zero-day turns CrowdStrike Falcon into an admin key

Security software designed to stop attackers can now be abused to gain local administrator rights.

Security researcher MSNightmare published FalconFlank, a zero-day exploit targeting the CrowdStrike Falcon Sensor. The proof-of-concept abuses the agent's malicious macro remediation feature to escalate privileges on fully updated Windows 11 25H2 and Windows Server 2025 machines running Phase 3 Optimal Protection. The repository picked up over 500 GitHub stars this week.

Why it matters: Security agents run with deep system access, turning any flaw in their remediation code into a high-value target. An attacker with basic access on a machine can use the endpoint agent itself to take full local control.

Know this: CrowdStrike likely has detections active for the unedited exploit payload. Testers looking to verify the bug in a lab will need to add exclusions or modify the payload's DLL loading technique.

Endpoint security tools remain the most trusted software on the machine—until they aren't.

Sources