CVE-2026-40058
Received Received - Intake

Arbitrary File Write in CrowdStrike Falcon Sensor for Windows

Vulnerability report for CVE-2026-40058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: CrowdStrike Holdings, Inc.

Description

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.Β  This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
crowdstrike falcon_sensor 7.34
crowdstrike falcon_sensor 7.32
crowdstrike falcon_sensor 7.16
crowdstrike laroux_malware_cleanup_tool *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in CrowdStrike's Falcon sensor for Windows where an arbitrary file write to protected locations can occur from an unprivileged context. It only exists when the Microsoft Office File Malicious Macro Removal policy setting is enabled. The issue is a Time-of-check Time-of-use (TOCTOU) race condition and could lead to local privilege escalation.

Detection Guidance

Detection involves checking the Falcon sensor version and policy settings. Use CrowdStrike's console to verify if the 'Microsoft Office File Malicious Macro Removal' policy is enabled and if the Cloud Anti-malware for Microsoft Office Files setting is active.

Impact Analysis

An attacker could exploit this to write files to protected locations on your system, potentially gaining elevated privileges. This could allow them to take control of your device or install malicious software.

Mitigation Strategies

Immediately update the Falcon sensor to the latest fixed versions (7.34+, 7.32 LTS, or 7.16 for Windows 7/2008 R2). If using the Laroux Malware Cleanup Tool, update it as well. Ensure Cloud Anti-malware for Microsoft Office Files is enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart