New CrowdStrike zero-day exploit grants SYSTEM privileges

An anonymous security researcher has released a zero-day exploit named FalconFlank that allows privilege escalation on fully updated Windows systems running CrowdStrike Falcon. BleepingComputer reports that the exploit abuses the security platform's office malicious macros remediation feature to spawn a command prompt with SYSTEM privileges.
CrowdStrike is investigating the claims and advises customers to disable a specific Microsoft Office Windows policy setting, according to BleepingComputer. Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by the researcher are real and operational.