Microsoft 0-day Hunter Releases Falcon Exploit: GadgetLad Reports

Nightmare Eclipse Shifts Attention Beyond Microsoft

The unhappy security researcher known as Nightmare Eclipse (also referred to as Chaotic Eclipse, Infinite Nightmare, and now MSNightmare) is redirecting their focus from their singular crusade against Microsoft to other companies. On Thursday, they unveiled a fresh zero-day vulnerability named FalconFlank that targets CrowdStrike’s Falcon endpoint security platform – though it does have a Windows connection.

FalconFlank: A New Menace

As per the prolific zero-day finder, FalconFlank represents a privilege escalation flaw that exploits the Microsoft Office harmful macros remediation feature within CrowdStrike Falcon. This automated security mechanism, integrated into the platform, scrutinizes Microsoft Office documents. If it detects any suspicious macros, it removes the questionable code and – hopefully – stops harmful code or other risky payloads from executing when the document is accessed.

CrowdStrike’s Reaction

“We are actively looking into these allegations and recommend customers disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike representative informed GadgetLad. “Clients are still protected through the Cloud Anti-malware for Microsoft Office Files configurations. We direct customers to the FalconFlank Tech Alert in the CrowdStrike support area.”

Exploit Testing on Windows

The proof-of-concept (PoC) exploit is effective on fully updated Windows 11 25H2 and Windows Server 2025 systems utilizing CrowdStrike Falcon with Phase 3 – Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse disclosed in a GitHub README. “Clearly by the time I release this, Crowdstrike would already have detections for it so if you wish to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load method,” they noted.

Kevin Beaumont Comments on the Expansion

Security investigator Kevin Beaumont verified that this exploit functions, along with several others Nightmare has introduced over the last week. Beaumont believes it’s not surprising to see Nightmare extending their efforts to non-Microsoft zero-days. “It makes sense that they’d expand to other vendors since there are issues throughout the endpoint security spectrum regarding the caliber of security products in terms of… security unfortunately,” Beaumont remarked to GadgetLad. “Hopefully this motivates cybersecurity vendors to elevate their standards, cease promoting hypothetical AI attacks, and instead secure their own offerings for clients.”

Additional Vulnerabilities Revealed

FalconFlank follows a series of vulnerabilities in various endpoint and antivirus solutions that Nightmare has uncovered recently. These include HardBreacher, a privilege escalation flaw within Kaspersky’s endpoint antivirus software. “The issue is now spilling over beyond Microsoft,” Nightmare stated when they released the HardBreacher PoC last week. “There was a poll conducted about finding a bug in either the home or commercial version, and the results favored the commercial version. At the time of this writing, the proof of concept functions on a completely patched Windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.”

Gen Digital and Avast Under Attack

Beaumont confirmed that Nightmare’s HardBreacher exploit code is operational, as is a PoC for an elevation of privileges vulnerability in Gen Digital’s Avast antivirus program. This zero-day, referred to as PrettyPrague, “will dump the SAM database by exploiting a flaw in Avast Sandbox and initiate a full SYSTEM shell,” according to the researcher.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could enable an attacker to elevate their system privileges,” Gen Digital told GadgetLad. “We promptly initiated our security response protocols and are actively working on a patch. We treat all security issues seriously and are dedicated to resolving this problem swiftly.”

Nvidia Receives a Break

Nightmare also recently disclosed an Nvidia memory corruption zero-day flaw dubbed GreenSection, but according to Beaumont, this one merely crashes the system. Nvidia has not responded to our inquiries.

Summary: Nightmare’s Whirlwind Tour

It seems Nightmare Eclipse has more zero-days in their arsenal than a dubious magician. From CrowdStrike to Kaspersky and even a playful jab at Avast, this researcher is making rounds like a tireless door-to-door salesman. Perhaps one day they’ll exhaust their list of vendors to target? One can only wish!