SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-40058

HIGH · CVSS 8.8 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the CrowdStrike Falcon sensor for Windows allows arbitrary file write to protected locations from an unprivileged context, potentially enabling local privilege escalation when the Microsoft Office File Malicious Macro Removal policy is enabled. Organizations using affected versions of the Falcon sensor (7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2) should prioritize applying the available security update to mitigate this high-severity risk. Additionally, users of the CrowdStrike Laroux Malware Cleanup Tool should also update to the latest version to ensure protection.

CVE
CVE-2026-40058
Severity
HIGH
CVSS
8.8
EPSS
0.08%
Microsoft Windows Office Linux

Original NVD Description

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.  This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.