CrowdStrike is investigating FalconFlank, a public proof-of-concept that allegedly enables local privilege escalation through Falcon Sensor’s Microsoft Office malicious-macro remediation workflow. Until the investigation is complete, the company recommends disabling the “Microsoft Office File Suspicious Macro Removal” Windows policy setting on affected Windows 11 25H2 and Windows Server 2025 systems.
Source