Skip to content

Security Advisory: FalconFlank Exploit Targeting CrowdStrike Falcon

FalconFlank Security Advisory
2:24

As part of our ongoing threat landscape monitoring, ISI Cyber wanted to share a recent development involving CrowdStrike Falcon.

An independent security researcher published a proof-of-conceptof concept exploit called FalconFlank on September 3, 2026.

WHAT HAPPENED

FalconFlank abuses CrowdStrike Falcon’s Microsoft Office Malicious Macro Removal feature and may allow an attacker who already has access to a Windows device to gain higher privileges.

Important: This is a local privilege escalation technique, not a remote internet-based attack. An attacker would first need access to the device before attempting to use it.

CURRENT CROWDSTRIKE GUIDANCE

CrowdStrike has confirmed that the affected feature is not available in US GOV 1 or US GOV 2, meaning Falcon GovCloud customers are not affected by this attack path.

CrowdStrike continues investigating the issue for commercial Falcon environments.

WHAT THIS MEANS FOR YOU

This is an advisory only. If your organization manages its own IT environment, the actions below are recommendations for your internal IT, security, or incident response team.

If your organization uses CrowdStrike Falcon:

  • Confirm whether your Falcon environment is GovCloud or commercial
  • If you use US GOV 1 or US GOV 2, CrowdStrike has confirmed the affected feature is not available and no FalconFlank specific configuration change is required
  • If you use a commercial Falcon environment, review CrowdStrike’s Tech Alert and determine whether the affected Microsoft Office Malicious Macro Removal feature is enabled
  • Follow CrowdStrike’s current mitigation guidance where applicable
  • Continue monitoring endpoint telemetry for suspicious privilege escalation or related activity

If you’re unsure which Falcon environment or policy configuration you use, please work with your internal IT team, CrowdStrike administrator, or security provider to validate your exposure.

We’ll continue monitoring the threat landscape and share meaningful updates as CrowdStrike’s investigation develops.

Regards,

Muhammad Ali
VP of Cybersecurity
ISI

REFERENCES

CrowdStrike, Tech Alert: FalconFlank Research

The Hacker News, Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The Register, CrowdStrike Investigates FalconFlank Research

Related Posts