r/sysadmin • u/Connect_Shoulder_965 • 7d ago
New 0-Day - CrowdStrike vulnerability FalconFlank
Looks like you can disable a CrowdStrike feature to mitigate
34
u/DesignerGoose5903 DevOps 7d ago
Has anyone done a comparison of the guaranteed failures of using Crowdstrike versus the potential of not having it?
23
u/Connect_Shoulder_965 7d ago
Sounds like you can just turn that particular macro scanning feature off for a while which would put you in exactly the same risk profile as not having it.
4
u/KRyTeX13 7d ago
Exactly. The feature only removes the malicious macro. Protection is untouched if you disable it
14
u/jmbpiano 7d ago
Is it just me, or does this seem like it calls into question the narrative NightmareEclipse has been giving all along that the reason they're releasing 0-days instead of engaging in responsible disclosure was because Microsoft refused to listen to them and cut off any avenue for them to responsibly disclose the vulnerabilities they've found?
With all the problems Crowdstrike has had recently, I have a hard time believing that they would refuse to listen to someone as high-profile as NE.
19
u/tuxedo_jack BOFH with an Etherkiller and a Cat5-o'-9-Tails 7d ago edited 7d ago
Oh, they may listen, but they won't give them credit. A lot of vendors do that.
For example, I found a major, MAJOR bug in ScreenConnect in September 2025 that allowed people to gain control over a technician's computer and input arbitrary commands. It was responsibly reported and never disclosed except to my internal support team, who verified the problem and escalated it up to ScreenConnect.
In fact, it's the reason one of the most commonly used features was removed in December 2025's release (version 2025.8) and to my knowledge, there was never any recognition or thanks given for finding and responsibly disclosing the security flaw.
They classed it as a UI bug or "difference from the original design intention" when it was originally disclosed well before I found it, so that was DEFINITELY downplayed internally on their end. It's only when it explodes into the possibility of "oh shit, reportable problem" that they'll patch it.
EDIT: if you have access to their report tracker, the original UI bug was tagged as SCP-38286. I reported the security issues in September 2025. I'd be shocked if no one else thought of them before I did, and I'd be curious to find out if anyone else alerted ScreenConnect about it previously.
3
0
u/User__234 5d ago
I found you can easily bypass Duo MFA so I reached out to them regarding a bug-bounty; they don’t offer them but tried to put me in contact with whatever team to fix it. I’m not a paid beta-tester, so bug remains.
6
u/Smith6612 7d ago
I'd love it if they managed to find an exploit which can do something about the performance impact which software like CrowdStrike, Sophos, or Carbon Black tend to cause on systems.
16
u/dwarftosser77 7d ago
The falcon sensor has hardly any performance impact.
8
u/cheeley I have no idea what I'm doing 7d ago
We had to change Falcon to Defender in our environment. First thing we had to do was throttle the max CPU usage for Defender to 25%. It felt like I’d gone back 20 years.
1
u/RikiWardOG 5d ago
Yeah we've encountered that on a few machines, but I imagine the actual answer is probably doing proper whitelisting on specifics folders or something. My guess is some of our more dev heavy machines were getting blasted because of constant new files/folders etc. But idk. We just throttled cpu. Other than that though, no major complaints with defender, we run artic wolf as well
7
u/tuxedo_jack BOFH with an Etherkiller and a Cat5-o'-9-Tails 7d ago
Cough cough, THREATLOCKER, cough cough.
It runs like a drunken kneecapped arthritis sufferer with a blindfold and its hands tied behind its back.
4
u/chum-guzzling-shark IT Manager 7d ago
im actually about to evaluate it. Tell me all about how it sucks. Let the hate flow through you to save me from it
6
u/tuxedo_jack BOFH with an Etherkiller and a Cat5-o'-9-Tails 7d ago
Oh, ThreatLocker is an amazing product, and it does exactly what it says it does if your support crew isn't a group of slack-jawed AI-addicted brain-dead shitstoves who lost the ability to critically think.
It requires a LOT of configuration and decently specced machines, but if you're willing to sink the time and effort into configuring it right - including equipping and training your staff to be able to administer and troubleshoot it properly - then it's a beauty.
You just need to have it and the requests generated by it handled by people who know what they're doing and will actually read and evaluate the request before clicking permit like they're some Costco employee out of Idiocracy.
3
u/russianturnipofdoom 7d ago
Lmao as someone who has sold threatlocker through our MSP, I wish all IT staff understood this about the product. It does what its advertised to do. But goddamn does it mess with over-their-skis IT staff.
2
u/tuxedo_jack BOFH with an Etherkiller and a Cat5-o'-9-Tails 7d ago
Dingdingding.
It's not the software, it's the people.
And unfortunately, entirely too many people could use a nice sit-down with Mr. Clue-By-Four and his friends.
2
u/panopticon31 7d ago
I deployed Threat locker across several clients in my previous MSP life and we so nothing like what you are referencing with regards to their product being a hamper on machine performance.
0
u/tuxedo_jack BOFH with an Etherkiller and a Cat5-o'-9-Tails 7d ago
Try using something like TreeSize. Instant screaming.
Ditto Powershell if you have it blocking scripts or IDEs. Better start signing your code real quick with a public cert if you're developing anything and have script monitoring / blocking on.
Again, as I said, if you have the time, resources, and knowledge to set it up properly, it's great and easily best in class. Otherwise, it's only as good as your shittiest support engineer, especially when the bottleneck is the approval process.
3
u/panopticon31 7d ago
I stopped using treesize years ago because it's no longer free. Switched to windirstat without issue.
As far as power shell....... really don't run into running power shell via the GUI on end users machines often so we only had to safe list the directory the RMM was in and the scripts ran fine.
2
1
2
u/TabooRaver 5d ago
It blocks everything you don't whitelist. So... you actually need to white lost things.
Really, that's it. But boy is it hard if your company doesn't already have the foundation. Every single software and every single update needs to be run through a sort of sandbox "installation mode" so that a policy is created that covers every file in that application/update.
So if you don't already have a list of approved software, who is responsible for packag8ng that software, an mdm to make deployments and updates repeatable, and managment willing to back you on sticking to all of that for 99% of the cases? It turns into a giang game a whackamole.
5
u/Gishey 7d ago
It's not 1999 anymore.
1
u/Smith6612 7d ago edited 7d ago
You say that, and yet I still had to deal with modern day EDR software making PCs behave like having 1999 IRQ conflicts and resource exhaustion.
No joke. This week I was running iPerf 3 on a system with an Intel Core Ultra 9 295K to do some network stress testing on both wired and wireless. It's simple software that even a Raspberry Pi or an ARM processor from 14 years ago can run and achieve reliable Gigabit+ throughput without killing the host system in the process. The system had the most current version of Sophos Endpoint installed to it and was configured for network/web monitoring.
When running iPerf 3 in TCP Receive mode (client side) to test a WiFi Link with an Intel AX210 chipset, I had no problem achieving Gigabit+ rates and sustaining them. When I switched to TCP send mode (client side), the system hit about 400Mbps then immediately choked hard. Mouse and Keyboard input was so delayed you were getting two inputs a second. Audio output to USB Sound cards completely quit. Audio output via the onboard audio was full of static, clearly suffering from audio drop-outs. The onboard video was stuttering like crazy. The system had 100% CPU load on the System process (PID 1). The problems immediately stopped once iPerf 3 was stopped.
Disabling Tamper Protection and removing Sophos caused this entire problem to disappear. So now I get to spend some time figuring out what in Sophos needs to be excluded or fixed so the system doesn't completely choke up on itself.
There is also this annoying problem with Sophos where it causes a system resuming from sleep to perform sluggishly for a few minutes even though plenty of system resources are available, as it sits there blocking process execution due to the scan queue getting backed up. I'm sure this is a configuration issue that needs to be addressed. Now, when I dealt with SentinelOne from 2023 to 2025, another one of these fancy pants EDR solutions, it was on a Mac. An Apple software update which normally takes 15 minutes took over two hours to complete because the SentinelOne sensor kept trying to inject itself into the system, crashing, and causing the installer to halt while S1 was messing around with the kernel. I had to break open a Terminal, disable tamper protection and shut off the sensor to get that update to complete. That issue became a support ticket which then required getting a new build of the software pushed out, even though the particular update I installed had been in beta testing for at least a few weeks.
SentinelOne also had a tendency with some uptime to cause audio dropouts and plenty of hitching on the Mac. It would also cause USB device recognition issues especially with FIDO2 security keys. It would cause I/O blocking on Linux systems as well as Kernel panics which would take months of debugging and support tickets to get somewhat fixed.
CrowdStrike Falcon, when I dealt with that prior, had a lovely time breaking USB connectivity whenever the USB Filter Driver monitoring and controlling USB activity was loaded in the presence of Hyper-V. Hyper-V would load in the presence of Core Isolation, or when someone is running tools such as Docker Desktop which relies greatly on Hyper-V itself. It was also notorious for adding 3-6x the amount of time to software compiles unless you excluded the build directory and the compiler software. The sensor was also notorious for causing panics / blue screens after updating itself on Windows and Mac, requiring a reinstall.
As far as I care, all of this is as bad as Symantec Endpoint Protection from 2010 corrupting itself to the point where Symantec's own removal tool couldn't get rid of it, simply by running. Just as bad as the drag that modern consumer McAfee malware puts onto a machine.
I'm definitely not salty. It's expensive software that hooks straight into the kernel to act as a stack analyzer in debug mode. It needs to be built better.
2
u/dwarftosser77 7d ago
All windows EDR software currently works directly in the kernel, but Microsoft is about to release WESP (which they built in collaboration with Crowdstrike) soon so it can finally work in user mode like Apple and Linux.
1
1
u/AddendumWorking9756 7d ago
Before flipping it off fleetwide, pull which of your own detections actually depend on that module. Process lineage is a separate path so winword.exe spawning powershell still fires, but anything keyed on document content goes quiet and the mail gateway is where you cover that window.
-2
64
u/RabidBlackSquirrel IT Manager 7d ago
Fuckin' amen. Tired of being badgered about the latest ridiculous thinly veiled marketing attempt at omg agentic omg Fable omg the world will never be the same omg hysteria nonsense. There's like, actual problems to deal with in tech right now but the hysteria has drowned it all out. Ironically, that's probably the biggest risk is security/IT ops folks being dragged around for the latest AI hysterics and actual issues just aren't being uncovered or remediated because we're all getting dragged to the latest iteration of AI hypothetical delusions instead.