As part of our ongoing threat landscape monitoring, ISI Cyber wanted to share a recent development involving CrowdStrike Falcon.
An independent security researcher published a proof-of-conceptof concept exploit called FalconFlank on September 3, 2026.
FalconFlank abuses CrowdStrike Falcon’s Microsoft Office Malicious Macro Removal feature and may allow an attacker who already has access to a Windows device to gain higher privileges.
Important: This is a local privilege escalation technique, not a remote internet-based attack. An attacker would first need access to the device before attempting to use it.
CrowdStrike has confirmed that the affected feature is not available in US GOV 1 or US GOV 2, meaning Falcon GovCloud customers are not affected by this attack path.
CrowdStrike continues investigating the issue for commercial Falcon environments.
This is an advisory only. If your organization manages its own IT environment, the actions below are recommendations for your internal IT, security, or incident response team.
If your organization uses CrowdStrike Falcon:
If you’re unsure which Falcon environment or policy configuration you use, please work with your internal IT team, CrowdStrike administrator, or security provider to validate your exposure.
We’ll continue monitoring the threat landscape and share meaningful updates as CrowdStrike’s investigation develops.
Regards,
Muhammad Ali
VP of Cybersecurity
ISI