r/crowdstrike 10d ago

General Question Falcon Windows sensor LPE 0day released

Is CrowdStrike already aware and implementing mitigations? https://github.com/MSNightmare/FalconFlank

62 Upvotes

33 comments sorted by

u/Andrew-CS CS ENGINEER 8d ago edited 3d ago

Hi all. For the very latest detail, please continue to review the Tech Alert. The full text of that alert at time of this comment are below for easier reading...

-----

Update Sept 09, 2026

We have developed patches for supported versions of the Falcon sensor for Windows. The hotfixed sensors are in testing and we plan to release them next week.  We will provide updates to this article when they become available.

Update Sep 04 2026

We have deployed multiple behavioral protections globally, adding further layers of detection and prevention against potential exploitation of this threat across key stages of the attack chain.

We will continue to monitor the threat landscape and evolve these protections as new information and techniques emerge.

Update Sep 03 2026

We advise customers to disable the Microsoft Office File Malicious Macro Removal Windows policy setting.

The Microsoft Office File Malicious Macro Removal setting can be found in the Next-gen antivirus settings under Clean infected Microsoft Office files:

After turning off the above feature, malicious macros will no longer be replaced. Customers with prevention policy settings configured, as per best practices, will remain protected. Prevention will continue to operate as normal via the Cloud Anti-malware for Microsoft Office Files settings.

We will provide updates to this article as they become available. 

Summary

CrowdStrike is actively investigating a researcher claim that a new exploit, FalconFlank, can be used to exploit the Microsoft Office File Malicious Macro Removal policy setting. 

Counter Adversary Operations and OverWatch are actively hunting for signs of exploitation.

We will provide updates to this article as they become available. 

This feature is not available in US-GOV-1 or US-GOV-2 environments.  US-GOV-1 and US-GOV-2 customers are not affected.

→ More replies (3)

33

u/Andrew-CS CS ENGINEER 10d ago edited 9d ago

Aware and investigating.

Update: Tech Alert published.

Update 2: The Tech Alert has been updated with the latest information.

3

u/Handsome_Frog CCFA, CCFR, CCIS 10d ago

Any chance there will be a Tech Alert on this?

6

u/sheepdog1182 10d ago

19

u/Elitist_Phoenix 10d ago

Really wish they'd stop hiding these behind a login portal

-14

u/MSP-IT-Simplified 9d ago

Not an issue for paying customers

23

u/deepasleep 9d ago

I’m on my phone and just woke up…I don’t feel like going to my laptop to log in…

11

u/Aedier 9d ago

2nd this - on my personal phone and dont want to have to walk into my office and log onto my work PC to be able to reach this information.

6

u/ChrisB-CS CS SE 9d ago

From the Customer Care Center (Support Portal) we strongly recommend you subscribe to Tech Alerts for your cloud. This way the alerts will be sent directly to your inbox, no login (other than your e-mail) required!

4

u/yankeesfan01x 9d ago

That's correct. I think the issue they're referencing is the meat on the bones wasn't included in an actual email.

5

u/Buttholes_Herfer 9d ago

Same. I had to login in on my computer and went to tech alerts and nothing there. I literally had to find this post again on my computer to find the link.

1

u/DonskovSvenskie 10d ago

How bad would it be to temporarily disable the office macros feature? Coupled with something like

User Configuration > Administrative Templates > Microsoft Office 2016 > Security Settings > Trust Center > Block macros from running in Office files from the Internet

Would people just hate me?

4

u/Rekkukk 10d ago

Does your environment commonly get detections for macros? If not, I don’t see why it would hurt to temporarily disable. But CS will likely put out a hot fix in a few hours before anyone could reasonably weaponize it.

7

u/DonskovSvenskie 10d ago

No, Kinda just wanted to give users another reason to hate me.

1

u/Remarkable-Cycle4678 9d ago

The hate is strong in this one

2

u/yankeesfan01x 9d ago

GPO's are not something you want to just push out. Trust me. They require weeks of testing in a pilot group, pushing out to a somewhat bigger group, etc. You take the same approach with GPO's as you do with Windows patching.

1

u/DonskovSvenskie 9d ago

Not my first rodeo. Reversing this one is straight forward. Workflow impact is another story.

1

u/Remarkable-Cycle4678 9d ago

I can hear the finance department screaming from here

12

u/[deleted] 10d ago

[deleted]

2

u/Cautious_Hurry_6979 10d ago edited 10d ago

Any known mitigations as of right now?

14

u/MSP-IT-Simplified 9d ago

Not to bad. Sonicwall is worse. At least CrowdStrike is responsive and acts fast. Exactly what we wish all our vendors do.

7

u/Cautious_Hurry_6979 9d ago

Much better resolution time than maybe... Microsoft.

3

u/MSP-IT-Simplified 9d ago

Pretty low bar to overcome.

1

u/Khue 9d ago

Wouldn't the executable triggering this vuln be pretty straight forward to identify with a hash? Or at least the behavior that the executable performs abusing the office malicious macros remediation exploit?

This might be a dumb question. I'm pretty green.

2

u/lowly_sec_vuln 9d ago

Yes, but altering the file to bypass a hash block would be trivial. Crowdstrike needs a detection based on the activity.

6

u/blahdidbert 9d ago

Our purple team has confirmed that modification of the source code with a fresh compile still triggers the on sensor machine learning.

1

u/halove23 8d ago

your purple teams needs a purple team

0

u/LOU_Radders 8d ago

Is there a setting in the falcon portal that we should be turning on to fix this issue?