The privesc path used by FalconFlank is a known issue. The exploited scheduled task and DLLs have been around for a minute.
What's that again about search order not being a security issue?
This is from May 2025.
Discussion
The privesc path used by FalconFlank is a known issue. The exploited scheduled task and DLLs have been around for a minute.
What's that again about search order not being a security issue?
This is from May 2025.
@mttaggart unquoted service paths, DLL hijacking, lib hijacking, scheduled talk hijacking, AV/EDR exclusion abuse. This is just the stuff I’ve personally done off the top of my head by taking advantage of search orders. I’m sure there’s more.
Here's a tool to confirm widespread vulnerability of the task, not just linked to Crowdstrike: https://github.com/bikini/marebackup-validation-kit