Junglewise Threat Intelligence

CVE-2026-40058: CrowdStrike Falcon sensor arbitrary file write in Office Macro Removal

CVE-2026-40058 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

CrowdStrike Falcon is an endpoint detection and response (EDR) security agent installed on Windows systems. The Falcon sensor contains an arbitrary file write vulnerability in its Microsoft Office macro removal feature that allows an unprivileged local attacker to write files to protected system locations, potentially leading to privilege escalation and system compromise. The vulnerability only manifests when the macro removal policy is enabled, and CrowdStrike has released immediate security updates.

Technical details

This is a CWE-367 time-of-check time-of-use (TOCTOU) race condition vulnerability in the Office macro removal feature of CrowdStrike Falcon for Windows. The vulnerability allows an unprivileged local attacker to exploit a race condition to write arbitrary files to protected file system locations, potentially leading to local privilege escalation. The vulnerability only affects Windows systems where the Microsoft Office File Malicious Macro Removal policy setting is enabled; affected versions range from 7.16 through 7.40 and 8.10 (with specific hotfixed builds identified in the advisory). The vulnerability was patched immediately upon disclosure with no indication of active exploitation in the wild.

Affected products

  • CrowdStrike Falcon sensor for Windows 7.16, 7.32, 7.33, 7.34-7.40, 8.10
  • CrowdStrike Laroux Malware Cleanup Tool 1.3.65.0 and earlier

Timeline

  • 2026-09-15: disclosed: CVE-2026-40058 advisory published
  • 2026-09-15: patched: Security updates available immediately

References