Arbitrary File Write Vulnerability in CrowdStrike Falcon Sensor for Windows
CVE-2026-40058
What is CVE-2026-40058?
CrowdStrike's Falcon sensor for Windows has a vulnerability that allows arbitrary file write to protected locations when the Microsoft Office File Malicious Macro Removal policy is active. This exposure could facilitate local privilege escalation, making it crucial for users to update to the latest versions. Affected versions include 7.34 and above, along with 7.32 LTS and 7.16 for Windows 7/2008 R2. Systems using the Falcon sensor for Mac, Linux, and Legacy Systems are not impacted. Additionally, the CrowdStrike Laroux Malware Cleanup Tool shares this vulnerability, and updates are available.
Affected Version(s)
Falcon sensor for Windows Windows 8.10.0 < 8.10.21408
Falcon sensor for Windows Windows 7.40.0 < 7.40.21309
Falcon sensor for Windows Windows 7.39.0 < 7.39.21113
