# CrowdStrike investigates Falcon privilege-escalation zero-day

_Friday, September 4, 2026 at 9:22 AM EDT · Security · Latest · Tier 1 — Major_

![CrowdStrike investigates Falcon privilege-escalation zero-day — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/04/CrowdStrike.jpg)

CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform.

The exploit is said to abuse Falcon's Office malicious-macros remediation feature. CrowdStrike advised customers to disable the related Microsoft Office File Suspicious Macro Removal policy while retaining Cloud Anti-malware for Microsoft Office Files settings. The flaw has no CVE identifier, but an independent security expert confirmed the released privilege-escalation exploits work.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/)

---
Canonical: https://techandbusiness.org/newswire/l2VfsoyosNB74seEZTVdrO
Retrieved: 2026-09-04T16:56:51.510Z
Publisher: Tech & Business (techandbusiness.org)
