CrowdStrike probes privilege-escalation exploit disclosure
CrowdStrike is investigating a publicly released proof-of-concept exploit that a security researcher says can elevate local privileges to SYSTEM level on Windows machines running its Falcon endpoint sensor. The exploit, dubbed FalconFlank, was published on GitHub on September 3 by a researcher using the names Nightmare Eclipse, Chaotic Eclipse and MSNightmare. The researcher described it as a zero-day privilege-escalation flaw that abuses Falcon Sensor’s Microsoft Office malicious-macro […]



