Couldn’t make Fal.Con? Get in on Fal.Con Digital. Learn more
Security Advisories

CVE-2026-40058 - Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows

Summary

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.

An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected. 

This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation.

The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.

Exploitation status

There is no indication of exploitation in the wild. Our threat hunting and intelligence team are continuously monitoring for signs of abuse or usage of this flaw.

Severity

CrowdStrike has scored this issue as 8.8 (HIGH) using the Common Vulnerability Scoring System Calculator v3.1 from NIST NVD.

Weakness Type and Impact

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
  • CAPEC-27: Leveraging Race Conditions via Symbolic Links

Performance impact

No direct or indirect impact to sensor performance is expected, nor was any seen in our testing.

Affected Sensors

CVE-2026-40058 affects the Falcon sensor for Windows when “Microsoft Office File Malicious Macro Removal” is enabled via host prevention policies.

The Windows sensor versions listed below are affected and will be hotfixed:

Affected VersionsHotfixed Builds

8.10.21405

8.10.21408 and later

7.40.21306

7.40.21309

7.39.21108

7.39.21105

7.39.21113

7.38.21003 LTS

7.38.21007 LTS and later 7.38 LTS Maintenance Releases

7.37.20907

7.37.20912

7.36.20805

7.36.20807

7.35.20709

7.35.20712

7.34.20610

7.34.20613

7.32.20406 LTS MR2

7.32.20405 LTS MR1

7.32.20403 LTS

7.32.20410 LTS

7.16.18642*

7.16.18637*

7.16.18635*

7.16.18632*

*Windows 7/2008 R2 only

7.16.18644*

*Windows 7/2008 R2 only

 

The Windows sensor versions listed below are affected but are no longer supported, and will not receive hotfixes. We recommend upgrading hosts running these versions to a supported and hotfixed release.

 

Affected VersionsAction to take

7.33

Upgrade to supported hotfix release listed above

7.31 and earlier

Upgrade to supported hotfix release listed above

 

The CrowdStrike Laroux Malware Cleanup Tool versions listed below are also affected and should be replaced with hotfixed versions.

 

Affected VersionsHotfixed build

1.3.65.0 and earlier

1.4.70.0

Remediation

Customers should upgrade Windows hosts running impacted sensor versions to a fixed version, and re-enable the Microsoft Office File Malicious Macro Removal Windows policy setting if previously disabled as a temporary mitigation.

Additional Questions

If you have additional questions, please reach out to your Technical Account Manager, Sales Engineer, Account Manager, or CrowdStrike Support.