Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows
Summary
| CVE | CVE-2026-40058 |
|---|---|
| State | PUBLISHED |
| Assigner | CrowdStrike |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-15 18:17:20 UTC |
| Updated | 2026-09-15 19:17:18 UTC |
| Description | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected. This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from 13ddcd98-6f4a-40a8-8e24-29ca0aee4661
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Problem Types: CWE-367 | CWE-367 CWE-367 Time-of-check time-of-use (TOCTOU) race condition
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 13ddcd98-6f4a-40a8-8e24-29ca0aee4661 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 8.10.0 8.10.21408 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.40.0 7.40.21309 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.39.0 7.39.21113 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.38.0 7.38.21007 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.37.0 7.37.20912 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.36.0 7.36.20807 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.35.0 7.35.20712 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.34.0 7.34.20613 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.33.0 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.32.0 7.32.20410 semver | Windows |
| CNA | CrowdStrike | Falcon Sensor For Windows | affected 7.16.0 7.16.18644 semver | Windows 7, Windows Server 2008 |
| CNA | CrowdStrike | Laroux Cleanup Tool | affected 1.0.20 1.4.70.0 semver | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.crowdstrike.com/en-us/security-advisories/cve-2026-40058 | 13ddcd98-6f4a-40a8-8e24-29ca0aee4661 | www.crowdstrike.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.