Summary
Researcher Chaotic Eclipse released two more zero-day exploits (FalconFlank and PrettyPrague) that allow local privilege escalation by abusing the remediation and sandbox features of CrowdStrike and Avast security software.
Take Action:
If you use CrowdStrike Falcon or Avast/Norton/AVG on Windows 11 or Windows Server 2025, watch closely for vendor patches and apply them the moment they are released. Don't assume your antivirus catching the public exploit code means the underlying flaw is fixed.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)