CrowdStrike Falcon 0day local privilege escalation exploit now public

thedealdirector · x · 2026-09-03

The FalconFlank 0day local privilege escalation (LPE) exploit for CrowdStrike Falcon is now public. The poster jokes about CrowdStrike's underslept, overworked engineers getting "aura farmed" by the disclosure.

For enterprises running Falcon EDR, this is an immediate concern: a public LPE PoC makes it far easier for attackers to escalate privileges on hosts with the agent installed.

Original post →

More from Safety

Safety channel →