03/09/2026
A researcher has published an unverified proof-of-concept claiming a zero-day privilege escalation in CrowdStrike Falcon Sensor dubbed FalconFlank. It reportedly abuses Falcon's Office macro remediation workflow to escalate from a low-privileged local user to SYSTEM.
Important context: CrowdStrike hasn't confirmed it. No CVE exists. No independent researcher has verified the exploit chain. Treat it as unconfirmed, not urgent.
But it's a useful reminder of a structural truth in endpoint security: EDR agents run with elevated privileges by design, because they have to quarantine, restore and remediate. That privilege is exactly what makes the agent itself worth watching, not just trusting.
It's why we don't treat any single agent as the final word on an incident — endpoint, identity and network signals get correlated before anything is called confirmed. One control shouldn't be both the thing that protects you and the only thing that tells you if it's failed.
Full breakdown, including what to actually check in your environment right now, on The C360 Lens 👇
A calm, evidence-led read of the FalconFlank claim against CrowdStrike Falcon Sensor: what's confirmed, what's unverified, and a practical response plan for MSPs and their clients.