Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-40058— Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows

Quick assessment

Affected
CrowdStrike Falcon sensor for Windows
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CrowdStrike 已发布安全更新,以修复 Windows 版 Falcon 传感器中的漏洞。该漏洞仅在启用“Microsoft Office 文件恶意宏移除”Windows 策略设置时存在;在此情况下,客户通过“云恶意软件防护(针对 Microsoft Office 文件)”设置仍可保持受保护状态。 该更新已立即适用于 Windows 7/2008 R2 系统的 7.34 及以上版本、7.32 LTS 以及 7.16 版本。Mac、Linux 和旧系统版的 Falcon 传感器不受此漏洞影响。 该漏洞可能导致

CVSS 8.8 · High

Possible ATT&CK Techniques 1 AI

T1543 · Create or Modify System Process

Affected Version Matrix 12

VendorProduct Version RangeStatus
CrowdStrike Falcon sensor for Windows 8.10.0< 8.10.21408 affected
7.40.0< 7.40.21309 affected
7.39.0< 7.39.21113 affected
7.38.0< 7.38.21007 affected
7.37.0< 7.37.20912 affected
7.36.0< 7.36.20807 affected
7.35.0< 7.35.20712 affected
7.34.0< 7.34.20613 affected
… +3 more rows
CrowdStrike Laroux Cleanup Tool 1.0.20< 1.4.70.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-40058

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows
Source: CVE Program / CVE List V5
Vulnerability Description
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.  This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
CrowdStrike Falcon sensor for Windows 8.10.0 ~ 8.10.21408 -
CrowdStrike Falcon sensor for Windows 7.16.0 ~ 7.16.18644 -
CrowdStrike Laroux Cleanup Tool 1.0.20 ~ 1.4.70.0 -

II. Public POCs for CVE-2026-40058

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-40058

登录查看更多情报信息。

Vendor Advisories for CVE-2026-40058 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-40058

No comments yet


Leave a comment