CrowdStrike Falcon zero-day privilege escalation

This Notice is intended for any unit IT professionals whose work at U-M involves CrowdStrike Falcon.

Summary

A security researcher has discovered a security flaw in the CrowdStrike Falcon Sensor. This flaw allows local privilege escalation, which could grant unauthorized users higher access rights.

Problem

The issue abuses CrowdStrike’s remediation workflow for malicious Microsoft Office macros on Windows systems. The flaw affects devices where the “Microsoft Office file malicious macro removal” capability is enabled.

Affected Systems

Windows 11 25H2 and Windows Server 2025 environments protected by CrowdStrike Falcon with Phase 3 Optimal Protection enabled.

Action Items

ITS Information Assurance has already confirmed that the recommended mitigation from CrowdStrike is implemented in the existing U-M CrowdStrike Falcon configuration.

How We Protect U-M

ITS provides CrowdStrike Falcon to units, which should be installed on all U-M owned systems (Windows, macOS, and Linux operating systems, whether workstations or servers). Falcon administrators in ITS and in U-M units use the Falcon console to investigate and remediate issues.

Questions, Concerns, Reports

Please contact ITS Information Assurance through the ITS Service Center.