Summary
- Public PoCs demonstrate local privilege-escalation issues affecting specific CrowdStrike Falcon and Avast configurations.
- CrowdStrike is investigating and has advised customers to disable a specific macro-removal setting; Gen Digital says it is developing a patch.
- A separate Nvidia disclosure involves memory corruption, but the currently demonstrated impact is less severe than the CrowdStrike and Avast PoCs.
Public proof-of-concept exploits targeting CrowdStrike Falcon and Avast Antivirus, alongside a separate Nvidia memory-corruption disclosure, are drawing attention to the attack surface created by software that operates with deep privileges on enterprise endpoints.
The disclosures were released by a researcher using several aliases, including Nightmare Eclipse, and have been given the names FalconFlank, PrettyPrague, and GreenSection.
The most consequential enterprise claim concerns CrowdStrike Falcon. FalconFlank is described as a local privilege-escalation vulnerability affecting functionality used by the Falcon sensor to remediate suspicious Microsoft Office macros.
The researcher says the proof of concept can obtain SYSTEM privileges on fully updated Windows systems when Falcon is running with a particular configuration. Independent security researcher Kevin Beaumont told The Register that he had reproduced the exploit.
CrowdStrike says it is investigating the claims and has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the issue is assessed. The company says customers remain protected through its cloud anti-malware settings for Microsoft Office files.
No evidence has been published of FalconFlank being used in an active enterprise intrusion campaign.
PrettyPrague targets Avast Antivirus and is also described as a local privilege-escalation flaw. The researcher says the vulnerability can abuse Avast sandbox functionality to access sensitive Windows data and obtain a SYSTEM shell.
Gen Digital, Avast’s parent company, has acknowledged a security vulnerability affecting a subset of its products that can allow an attacker to elevate privileges and says it is developing a patch.
The Nvidia disclosure requires more cautious treatment. GreenSection concerns memory corruption involving Nvidia user-mode components and shared memory, but independent testing reported to The Register produced a system crash rather than the SYSTEM-level privilege escalation demonstrated for the other two issues.
The three disclosures should therefore not be treated as equivalent zero-days with identical consequences. They share a researcher and a short publication window, but the validation status, vendor response, prerequisites, and demonstrated impact differ.
The common enterprise issue is the amount of privilege carried by the affected software. Endpoint security products, drivers, and low-level system components need access ordinary applications do not have in order to inspect processes, manipulate files, load components, or intervene in malicious activity.
Those privileges are necessary for the products’ intended function, but they also increase the consequence when a vulnerability exists inside the privileged component.
Endpoint detection and response software is an especially sensitive example. The product is trusted by the operating system, centrally managed, widely deployed, and deliberately capable of taking actions across the endpoint. A weakness that turns a remediation function into a privilege-escalation route can therefore invert a defensive capability.
The disclosures also demonstrate the operational difficulties of uncoordinated proof-of-concept publication. Public technical details can become available before a vendor has completed its investigation, issued a CVE, or distributed a patch, leaving customers to make configuration decisions while the technical position is still developing.
Public PoC code does not establish active exploitation. There is currently no evidence of a broad campaign using FalconFlank, PrettyPrague, or GreenSection against organisations.
The immediate risk instead lies in the interval between disclosure and remediation. CrowdStrike is investigating and has issued temporary configuration guidance, Gen Digital is developing a patch, and the practical security impact of the Nvidia issue remains more limited on the evidence currently available.
The disclosures nevertheless reinforce a basic vulnerability-management problem: software deployed to defend endpoints remains part of the endpoint’s privileged code base. Its security failures can carry consequences at least as serious as those found in the applications it monitors.





