decrypted · 5 september 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law

CrowdStrike's macro clean-up tool turns into a SYSTEM shell

When your endpoint protection software has the standing power to delete files as SYSTEM, the only real question is how that power gets misused, not whether. This week a researcher published exactly that answer for CrowdStrike's Falcon sensor: a working exploit, no CVE yet, that turns a "clean up malicious macros" feature into a route to a SYSTEM command prompt on a fully patched Windows 11 machine.

A cleaner with a master key

Falcon can automatically strip suspicious macros out of Office documents. To do that job anywhere on disk, the process doing the stripping runs with SYSTEM privileges, higher than the logged-in user who triggered it. The researcher, who publishes under the handle Nightmare Eclipse and has a track record of releasing proof-of-concept exploits for Microsoft products, found that a specially crafted file could persuade that SYSTEM-level cleaner to spawn a command prompt instead of just doing its cleaning. The result, dubbed FalconFlank, works against up to date Windows 11 25H2 and Windows Server 2025 machines running Falcon with CrowdStrike's own top protection tier switched on.

CrowdStrike has not confirmed the flaw with a CVE or shipped a fix. It has told customers to disable the "Microsoft Office File Suspicious Macro Removal" Windows policy setting and rely on its cloud anti-malware protection instead while it investigates. That is the one line UK IT teams should act on this morning: check whether that policy setting is switched on, and turn it off until CrowdStrike says otherwise.

The Secure by Design lesson

This is not really a coding bug story. It is a design pattern story: any feature built to act on your behalf with more privilege than you have is a lever, and security software is full of these levers because it needs elevated access to do its job, scanning files, quarantining processes, rewriting registry keys. The mistake is trusting the input that triggers the lever as much as the code that pulls it. A macro-removal routine that runs as SYSTEM has to treat the file it is cleaning as hostile, not as a passive target.

The same researcher has spent this week releasing comparable privilege escalation proofs of concept against Kaspersky and Avast, and a crash bug against Nvidia. None of that makes any single vendor careless. It does mean UK organisations should stop treating "it is security software" as a reason to skip the question every other vendor gets asked: what happens if the input this tool trusts is actually attacker controlled, and does it need SYSTEM to answer that question at all.

Also this week

The Cyber Security and Resilience Bill reached House of Lords committee stage this week, with peers beginning line by line scrutiny on 1 and 3 September. The bill would pull data centres and medium to large managed service providers into the NIS regime for the first time, with 24 hour initial breach notification, 72 hour full reports, and penalties of £17 million or 4% of turnover, whichever is higher. The catch, raised repeatedly in committee, is that the detail peers actually need, what counts as a "significant" incident, how data centres report, board accountability, is being deferred to secondary legislation and a consultation that has not started. UK organisations in scope have time to prepare for the principle, but not yet the practice.

A ransomware crew calling itself Qilin claimed a UK business services and packaging firm, Complete Packaging Solutions, on its leak site on 4 September, threatening to publish stolen files unless the company gets in touch. The company has not confirmed the claim publicly, and a leak site posting is a claim, not proof, but Qilin has been one of the most prolific ransomware brands this year and has generally followed through on similar threats.

A new Cloud Security Index from Intruder, covering 3,000 organisations over the past 12 months, found 76% of AWS accounts had at least one exposed service, against 64% on Azure and just 8% on Google Cloud, with almost no overlap in which misconfigurations dominate on each platform. For the majority of UK organisations now running more than one cloud provider, that means the security playbook that works on one platform will not catch what is wrong on another, and that gap is where control over your own estate quietly erodes.

Sources

Thinking through what any of this means for your own systems? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.