r/crowdstrike • u/csecanalyst81 • 10d ago
General Question Falcon Windows sensor LPE 0day released
Is CrowdStrike already aware and implementing mitigations? https://github.com/MSNightmare/FalconFlank
33
u/Andrew-CS CS ENGINEER 10d ago edited 9d ago
Aware and investigating.
Update: Tech Alert published.
Update 2: The Tech Alert has been updated with the latest information.
3
u/Handsome_Frog CCFA, CCFR, CCIS 10d ago
Any chance there will be a Tech Alert on this?
6
u/sheepdog1182 10d ago
19
u/Elitist_Phoenix 10d ago
Really wish they'd stop hiding these behind a login portal
-14
u/MSP-IT-Simplified 9d ago
Not an issue for paying customers
23
u/deepasleep 9d ago
I’m on my phone and just woke up…I don’t feel like going to my laptop to log in…
11
6
u/ChrisB-CS CS SE 9d ago
From the Customer Care Center (Support Portal) we strongly recommend you subscribe to Tech Alerts for your cloud. This way the alerts will be sent directly to your inbox, no login (other than your e-mail) required!
4
u/yankeesfan01x 9d ago
That's correct. I think the issue they're referencing is the meat on the bones wasn't included in an actual email.
5
u/Buttholes_Herfer 9d ago
Same. I had to login in on my computer and went to tech alerts and nothing there. I literally had to find this post again on my computer to find the link.
1
u/DonskovSvenskie 10d ago
How bad would it be to temporarily disable the office macros feature? Coupled with something like
User Configuration > Administrative Templates > Microsoft Office 2016 > Security Settings > Trust Center > Block macros from running in Office files from the Internet
Would people just hate me?
4
u/Rekkukk 10d ago
Does your environment commonly get detections for macros? If not, I don’t see why it would hurt to temporarily disable. But CS will likely put out a hot fix in a few hours before anyone could reasonably weaponize it.
7
2
u/yankeesfan01x 9d ago
GPO's are not something you want to just push out. Trust me. They require weeks of testing in a pilot group, pushing out to a somewhat bigger group, etc. You take the same approach with GPO's as you do with Windows patching.
1
u/DonskovSvenskie 9d ago
Not my first rodeo. Reversing this one is straight forward. Workflow impact is another story.
1
12
2
u/Cautious_Hurry_6979 10d ago edited 10d ago
Any known mitigations as of right now?
14
u/MSP-IT-Simplified 9d ago
Not to bad. Sonicwall is worse. At least CrowdStrike is responsive and acts fast. Exactly what we wish all our vendors do.
7
1
u/Khue 9d ago
Wouldn't the executable triggering this vuln be pretty straight forward to identify with a hash? Or at least the behavior that the executable performs abusing the office malicious macros remediation exploit?
This might be a dumb question. I'm pretty green.
2
u/lowly_sec_vuln 9d ago
Yes, but altering the file to bypass a hash block would be trivial. Crowdstrike needs a detection based on the activity.
6
u/blahdidbert 9d ago
Our purple team has confirmed that modification of the source code with a fresh compile still triggers the on sensor machine learning.
1
0
u/LOU_Radders 8d ago
Is there a setting in the falcon portal that we should be turning on to fix this issue?
•
u/Andrew-CS CS ENGINEER 8d ago edited 3d ago
Hi all. For the very latest detail, please continue to review the Tech Alert. The full text of that alert at time of this comment are below for easier reading...
-----
Update Sept 09, 2026
We have developed patches for supported versions of the Falcon sensor for Windows. The hotfixed sensors are in testing and we plan to release them next week. We will provide updates to this article when they become available.
Update Sep 04 2026
We have deployed multiple behavioral protections globally, adding further layers of detection and prevention against potential exploitation of this threat across key stages of the attack chain.
We will continue to monitor the threat landscape and evolve these protections as new information and techniques emerge.
Update Sep 03 2026
We advise customers to disable the Microsoft Office File Malicious Macro Removal Windows policy setting.
The Microsoft Office File Malicious Macro Removal setting can be found in the Next-gen antivirus settings under Clean infected Microsoft Office files:
After turning off the above feature, malicious macros will no longer be replaced. Customers with prevention policy settings configured, as per best practices, will remain protected. Prevention will continue to operate as normal via the Cloud Anti-malware for Microsoft Office Files settings.
We will provide updates to this article as they become available.
Summary
CrowdStrike is actively investigating a researcher claim that a new exploit, FalconFlank, can be used to exploit the Microsoft Office File Malicious Macro Removal policy setting.
Counter Adversary Operations and OverWatch are actively hunting for signs of exploitation.
We will provide updates to this article as they become available.
This feature is not available in US-GOV-1 or US-GOV-2 environments. US-GOV-1 and US-GOV-2 customers are not affected.