Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare Eclipse, has released a new proof of concept for a zero day privilege escalation vulnerability named FalconFlank that affects CrowdStrike Falcon. According to the researcher, the vulnerability exploits the Office malicious macros remediation feature within the CrowdStrike Falcon Sensor. The proof of concept has been published on GitHub, where the researcher noted that CrowdStrike may already have detection mechanisms for the issue. They also stated that anyone testing the proof of concept may need to add exclusions or modify the code and its DLL loading technique to avoid detection. The researcher said the exploit functions on fully updated Windows 11 25H2 systems and Windows Server 2025 running CrowdStrike Falcon. CrowdStrike has been contacted for comment, but no public response had been issued at the time of reporting.
The disclosure follows a series of similar vulnerability demonstrations released by the same researcher. Only days earlier, Chaotic Eclipse published a proof of concept called HardBreacher targeting Kaspersky Endpoint Security for Windows version 14.0.0.504. According to the researcher, the exploit may require several attempts before executing successfully, after which it creates a DLL file within the Windows System32 directory with full permissions assigned to the current user. The researcher stated that gaining control of the Kaspersky user interface process could interfere with the product’s functionality and alter file access behavior. Kaspersky confirmed that the issue has been resolved and said the fix has been distributed through automatic database updates, while users can also install it by manually updating their databases. The recent disclosure adds to an ongoing series of research projects focused on endpoint security products from major cybersecurity vendors.
Last month, the researcher also introduced another proof of concept known as ShieldBreak, identified as CVE 2026 69414, which targets Microsoft Defender. The vulnerability is described as a local privilege escalation issue capable of allowing arbitrary code execution with NT AUTHORITY SYSTEM privileges. Researchers have assessed it as a patch bypass for CVE 2026 50656, also known as RoguePlanet, and Microsoft has not yet released a security update. According to analysis from LevelBlue, ShieldBreak combines several Windows technologies, including Cloud Files, Object Manager namespace manipulation, direct Windows Defender API invocation, and a timing race within the remediation process. This combination enables Windows Defender to write an attacker supplied DLL into the System32 directory before executing it through the built in Windows Error Reporting task, creating a complete privilege escalation chain.
Chaotic Eclipse has also commented publicly on the vulnerability disclosure process, stating that communication with Microsoft regarding reported issues has been limited. The researcher said these circumstances have made it difficult to coordinate vulnerability reporting with affected vendors. In public posts published during August 2026, the researcher indicated that future disclosures involving third party vendors could be released before Microsoft’s regular Patch Tuesday updates if communication challenges continue. The latest FalconFlank release, together with the previously published HardBreacher and ShieldBreak proof of concepts, highlights continued research into privilege escalation techniques affecting widely deployed endpoint protection platforms and underscores the importance of timely security updates and coordinated vulnerability management across the cybersecurity industry.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





