Arbitrary File Write Vulnerability in CrowdStrike Falcon Sensor for Windows
CVE-2026-40058

8.8HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-40058?

CrowdStrike's Falcon sensor for Windows has a vulnerability that allows arbitrary file write to protected locations when the Microsoft Office File Malicious Macro Removal policy is active. This exposure could facilitate local privilege escalation, making it crucial for users to update to the latest versions. Affected versions include 7.34 and above, along with 7.32 LTS and 7.16 for Windows 7/2008 R2. Systems using the Falcon sensor for Mac, Linux, and Legacy Systems are not impacted. Additionally, the CrowdStrike Laroux Malware Cleanup Tool shares this vulnerability, and updates are available.

Affected Version(s)

Falcon sensor for Windows Windows 8.10.0 < 8.10.21408

Falcon sensor for Windows Windows 7.40.0 < 7.40.21309

Falcon sensor for Windows Windows 7.39.0 < 7.39.21113

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.