Impact
This vulnerability allows an attacker operating from an unprivileged Windows context to write files to protected system locations, which can then be used to elevate privileges. The flaw is related to the Office Macro Removal policy setting when the CrowdStrike Falcon sensor for Windows is enabled. The weakness is identified as CWE‑367.
Affected Systems
CrowdStrike Falcon sensor for Windows is affected in versions 7.34 and above, 7.32 LTS, and 7.16 on Windows 7 and Windows Server 2008 R2 systems, as well as the CrowdStrike Laroux Cleanup Tool that implements the same feature. The Falcon sensor for Mac, Linux, and legacy systems are not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8. The EPSS score is 0.00083, indicating a very low probability of exploitation, and it is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Based on the description, it is inferred that exploitation requires local access to a Windows machine where the Office Macro Removal policy is enabled; the attacker does not need network or elevated privileges to gain initial foothold. The potential impact is a local privilege escalation that could grant the attacker the ability to modify protected system files.
OpenCVE Enrichment