An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.
This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation.
The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected. This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately. | |
| Title | Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows | |
| First Time appeared |
Crowdstrike
Crowdstrike cslarouxcleanuptool Crowdstrike falcon |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:crowdstrike:cslarouxcleanuptool:*:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.16:*:*:*:*:windows_7:*:* cpe:2.3:a:crowdstrike:falcon:7.16:*:*:*:*:windows_server_2008:*:* cpe:2.3:a:crowdstrike:falcon:7.32:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.33:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.34:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.35:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.36:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.37:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.38:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.39:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:7.40:*:*:*:*:windows:*:* cpe:2.3:a:crowdstrike:falcon:8.10:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Crowdstrike
Crowdstrike cslarouxcleanuptool Crowdstrike falcon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CrowdStrike
Published:
Updated: 2026-09-15T18:04:52.198Z
Reserved: 2026-04-08T18:55:21.491Z
Link: CVE-2026-40058
Updated: 2026-09-15T18:04:36.919Z
Status : Received
Published: 2026-09-15T18:17:20.913
Modified: 2026-09-15T18:17:20.913
Link: CVE-2026-40058
No data.
OpenCVE Enrichment
No data.