{"id":11996,"date":"2026-09-03T11:02:28","date_gmt":"2026-09-03T17:02:28","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/"},"modified":"2026-09-29T13:01:39","modified_gmt":"2026-09-29T19:01:39","slug":"alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/","title":{"rendered":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR)<\/strong><\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Vulnerable configuration<\/strong><\/td><td><strong>Operating system<\/strong><\/td><\/tr><tr><td><strong>CrowdStrike Falcon Sensor<\/strong><\/td><td>Phase 3 \u2014 Optimal Protection with &#8220;Microsoft Office file malicious macro removal&#8221; enabled<\/td><td>Windows 11 25H2 (fully updated)<\/td><\/tr><tr><td><strong>CrowdStrike Falcon Sensor<\/strong><\/td><td>Phase 3 \u2014 Optimal Protection with &#8220;Microsoft Office file malicious macro removal&#8221; enabled<\/td><td>Windows Server 2025 (fully updated)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">A possible 0-day <strong>local privilege escalation (LPE)<\/strong> vulnerability affecting the <strong>CrowdStrike Falcon Sensor<\/strong> has been reported, and the source code and compiled binary of the exploit \u2014 dubbed <strong>FalconFlank<\/strong> \u2014 have been published.<strong> <\/strong>There is still no official statement from Crowdstrike.<\/p>\n\n<p class=\"wp-block-paragraph\">The flaw abuses the remediation mechanism of <strong>malicious macros in Microsoft Office files<\/strong> \u2014 a feature that operates with elevated privileges within the sensor \u2014 to escalate the privileges of an unprivileged local user to <strong>SYSTEM<\/strong> level on fully updated Windows systems.<\/p>\n\n<figure class=\"wp-block-image size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" width=\"683\" height=\"1024\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/download-683x1024.png\" alt=\"\" class=\"wp-image-11706\" style=\"width:448px;height:auto\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/download-683x1024.png 683w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/download-200x300.png 200w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/download-768x1152.png 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/download.png 1024w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/figure>\n\n<p class=\"has-text-align-center wp-block-paragraph\">Figure 1 FalconFlank exploitation flow<\/p>\n\n<p class=\"wp-block-paragraph\">The researcher stated that the proof of concept worked in fully updated <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-antivirus-turned-off\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows 11 25H2 and Windows Server 2025<\/a> environments protected by CrowdStrike Falcon with Phase 3 optimal protection enabled.<\/p>\n\n<p class=\"wp-block-paragraph\">The public repository was recently created and includes C source code, a Visual Studio solution, project files, header files, and a release directory compiled for x64.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"774\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/image-1024x774.jpeg\" alt=\"\" class=\"wp-image-11704\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/image-1024x774.jpeg 1024w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/image-300x227.jpeg 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/image-768x580.jpeg 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/image.jpeg 1032w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<p class=\"has-text-align-center wp-block-paragraph\">Figure 2 &#8211; Evidence of the PoC published by the researcher.<\/p>\n\n<p class=\"wp-block-paragraph\">CrowdStrike has already issued a statement reporting that it is investigating the matter and recommends temporarily disabling the feature. When doing so, malicious macros will no longer be replaced automatically, but protection will continue to function normally through Cloud Anti-malware for Microsoft Office Files, provided that policies are configured according to best practices.<\/p>\n\n<p class=\"wp-block-paragraph\">Additionally, the exploit is already detected by Crowdstrike; however, an attacker may be able to evade that detection, so it is essential to apply mitigation until a patch for the vulnerability is available.<\/p>\n\n<h2 class=\"wp-block-heading\">\u00a0<\/h2>\n\n<h2 class=\"wp-block-heading\">Mitigation<\/h2>\n\n<p class=\"wp-block-paragraph\">While CrowdStrike issues an official patch:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Disable the option &#8220;Microsoft Office File Suspicious Macro Removal&#8221;<\/strong> within the Windows prevention policy, located at <em>Next-gen antivirus &gt; Clean infected Microsoft Office files<\/em>.<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>Monitor the creation of DLL files in system directories<\/strong> (C:\\Windows\\System32\\) from Falcon Sensor processes or unexpected child processes.\n<ul class=\"wp-block-list\">\n<li>Especially monitor any detection alert for the FalconFlank exploit<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Monitor the CrowdStrike repository<\/strong> (https:\/\/supportportal.crowdstrike.com) for the issuance of an official advisory or sensor update.<\/li>\n\n\n\n<li>Keep in mind that the attacker <strong>must have prior local access<\/strong> \u2014 reinforce access controls, multi-factor authentication, and least privilege policies on all endpoints protected with Falcon.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">For Cybolt Managed Services customers, the SOC team has already applied the mitigations, so no additional action is required at this time.<\/p>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><strong>For follow-up:<\/strong><ul><li>CrowdStrike Support Portal: https:\/\/supportportal.crowdstrike.com<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>CrowdStrike Security Advisories: <a href=\"https:\/\/www.crowdstrike.com\/blog\/category\/security-advisories\/\">https:\/\/www.crowdstrike.com\/blog\/category\/security-advisories\/<\/a><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>https:\/\/cybersecuritynews.com\/crowdstrike-falcon-0-day\/<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"featured_media":11709,"template":"","class_list":["post-11996","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"536\" \/>\n\t\t<meta property=\"og:image:height\" content=\"349\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-03T17:02:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T19:01:39+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#listItem\",\"name\":\"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/\",\"name\":\"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab\",\"description\":\"Affected product(s): CrowdStrike Falcon Sensor \\u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \\u2014 dubbed FalconFlank \\u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/crowdstrike.jpeg\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#mainImage\",\"width\":536,\"height\":349},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\\\/#mainImage\"},\"datePublished\":\"2026-09-03T11:02:28-06:00\",\"dateModified\":\"2026-09-29T13:01:39-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab","description":"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#listItem","name":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#listItem","position":2,"name":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/","name":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab","description":"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#mainImage","width":536,"height":349},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/#mainImage"},"datePublished":"2026-09-03T11:02:28-06:00","dateModified":"2026-09-29T13:01:39-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab","og:description":"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg","og:image:width":536,"og:image:height":349,"article:published_time":"2026-09-03T17:02:28+00:00","article:modified_time":"2026-09-29T19:01:39+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon - Beacon Lab","twitter:description":"Affected product(s): CrowdStrike Falcon Sensor \u2014 Endpoint security platform (EDR) Description A possible 0-day local privilege escalation (LPE) vulnerability affecting the CrowdStrike Falcon Sensor has been reported, and the source code and compiled binary of the exploit \u2014 dubbed FalconFlank \u2014 have been published. There is still no official statement from Crowdstrike. The flaw abuses","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/crowdstrike.jpeg"},"aioseo_meta_data":{"post_id":"11996","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 19:00:38","updated":"2026-09-29 20:56:20","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-95 0-Day Privilege Escalation via Abuse of MS Office Macros Remediation in Crowdstrike Falcon","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-95-0-day-privilege-escalation-via-abuse-of-ms-office-macros-remediation-in-crowdstrike-falcon\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11996\/revisions"}],"predecessor-version":[{"id":11997,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11996\/revisions\/11997"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11709"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}