← All Briefings
Briefings


CrowdStrike Falcon Zero-Day Grants SYSTEM On Patched Machines

A researcher using the handle "Nightmare Eclipse" released a zero-day exploit named "FalconFlank" that escalates a local attacker to SYSTEM on Windows machines running a fully patched CrowdStrike Falcon sensor. Falcon is the kernel-level agent that inspects every process on the endpoint, which is the point: the exploit lives in the trust boundary the sensor itself occupies, not in some peripheral service riding alongside it. CrowdStrike has not shipped a fix. The vendor's own product is now the highest-privilege thing on the box for an attacker who is already local.

HKMA's TM-G-1 module treats endpoint detection coverage as a control a bank cites when a regulator asks how it detects lateral movement after initial access. That citation now needs a footnote: coverage is not the same claim as "cannot be turned into a privilege-escalation primitive by the thing providing the coverage." A bank running Falcon across its estate has no patch to apply, so the only working control is host isolation and just-in-time local admin removal until CrowdStrike ships one, and today's CVE digest carries a second reminder of the same asymmetry: CVE-2026-16232, a 9.3 authentication bypass in Check Point's SmartConsole login process, has sat on CISA's Known Exploited Vulnerabilities list since 22 July with a 72% EPSS score, which is a fully patchable bug still being exploited seven weeks after the fix existed.

Neither gap closes with a vendor statement. CrowdStrike will patch FalconFlank eventually; Check Point already patched CVE-2026-16232 in July and it is still getting exploited, which is a deployment failure, not a vendor failure. The control that matters this week is not "which EDR vendor," it is whether the bank's patch-management SLA for CISA KEV entries is measured in days or in the quarter it happens to fall in. For CVE-2026-16232, seven weeks has already been too long.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.