Description
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.




An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected. 




This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation.




The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker operating from an unprivileged Windows context to write files to protected system locations, which can then be used to elevate privileges. The flaw is related to the Office Macro Removal policy setting when the CrowdStrike Falcon sensor for Windows is enabled. The weakness is identified as CWE‑367.

Affected Systems

CrowdStrike Falcon sensor for Windows is affected in versions 7.34 and above, 7.32 LTS, and 7.16 on Windows 7 and Windows Server 2008 R2 systems, as well as the CrowdStrike Laroux Cleanup Tool that implements the same feature. The Falcon sensor for Mac, Linux, and legacy systems are not affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8. The EPSS score is 0.00083, indicating a very low probability of exploitation, and it is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Based on the description, it is inferred that exploitation requires local access to a Windows machine where the Office Macro Removal policy is enabled; the attacker does not need network or elevated privileges to gain initial foothold. The potential impact is a local privilege escalation that could grant the attacker the ability to modify protected system files.

Generated by OpenCVE AI on September 20, 2026 at 14:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest update to the CrowdStrike Falcon sensor for Windows for versions 7.34 and above, 7.32 LTS, and 7.16 on Windows 7/2008 R2.
  • Apply the latest update to the CrowdStrike Laroux Cleanup Tool.
  • Disable the Microsoft Office File Malicious Macro Removal Windows policy setting if immediate patching is not possible.
  • Consider monitoring for anomalous writes to protected system files.

Generated by OpenCVE AI on September 20, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Crowdstrike falcon Sensor For Windows
Vendors & Products Crowdstrike falcon Sensor For Windows

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.  This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.
Title Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows
First Time appeared Crowdstrike
Crowdstrike cslarouxcleanuptool
Crowdstrike falcon
Weaknesses CWE-367
CPEs cpe:2.3:a:crowdstrike:cslarouxcleanuptool:*:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.16:*:*:*:*:windows_7:*:*
cpe:2.3:a:crowdstrike:falcon:7.16:*:*:*:*:windows_server_2008:*:*
cpe:2.3:a:crowdstrike:falcon:7.32:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.33:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.34:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.35:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.36:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.37:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.38:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.39:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:7.40:*:*:*:*:windows:*:*
cpe:2.3:a:crowdstrike:falcon:8.10:*:*:*:*:windows:*:*
Vendors & Products Crowdstrike
Crowdstrike cslarouxcleanuptool
Crowdstrike falcon
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Crowdstrike Cslarouxcleanuptool Falcon Falcon Sensor For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: CrowdStrike

Published:

Updated: 2026-09-15T18:04:52.198Z

Reserved: 2026-04-08T18:55:21.491Z

Link: CVE-2026-40058

cve-icon Vulnrichment

Updated: 2026-09-15T18:04:36.919Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:20.913

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-40058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition