TOCTOU arbitrary file write can enable local privilege escalation in CrowdStrike Falcon sensor for Windows

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-40058?

CVE-2026-40058 is a vulnerability classified as Time-of-check Time-of-use (TOCTOU) Race Condition, affecting Falcon sensor for Windows (affected versions: 8.10.0 – < 8.10.21408, 7.40.0 – < 7.40.21309, and other affected versions) and Laroux Cleanup Tool (affected versions: 1.0.20 – < 1.4.70.0). This vulnerability is rated High, with a CVSS score of 8.8. Current sources do not report this vulnerability as exploited.

Overview

Original source data

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and 7.16 for Windows 7/2008 R2 systems. The Falcon sensor for Mac, Linux, and Legacy Systems are not affected.  This vulnerability could expose an arbitrary file write to protected locations from an unprivileged context, potentially leading to local privilege escalation. The CrowdStrike Laroux Malware Cleanup Tool, based off of the same feature in the CrowdStrike Falcon sensor for Windows, is also affected. An update for this tool is also available immediately.

Affected products and scope

  • CrowdStrike Falcon sensor for Windows: The vulnerability applies only when the Microsoft Office File Malicious Macro Removal policy is enabled. The normalized record identifies affected ranges of 8.10.0 through versions less than 8.10.21408, 7.40.0 through versions less than 7.40.21309, 7.39.0 through versions less than 7.39.21113, 7.38.0 through versions less than 7.38.21007, 7.37.0 through versions less than 7.37.20912, 7.36.0 through versions less than 7.36.20807, 7.35.0 through versions less than 7.35.20712, 7.34.0 through versions less than 7.34.20613, 7.32.0 through versions less than 7.32.20410, and 7.16.0 through versions less than 7.16.18644 on Windows 7 or Windows Server 2008 R2. The corresponding hotfixed builds are 8.10.21408 and later within the 8.10 branch, 7.40.21309, 7.39.21113, 7.38.21007 LTS and later 7.38 LTS maintenance releases, 7.37.20912, 7.36.20807, 7.35.20712, 7.34.20613, 7.32.20410 LTS, and 7.16.18644 for Windows 7 or Windows Server 2008 R2.
  • Unsupported branches: CrowdStrike also lists 7.33, 7.31, and earlier versions as affected but no longer supported, with no hotfix for those branches. These systems should be upgraded to a supported hotfixed release. The normalized record explicitly lists 7.33.0, so the detailed status of older builds should follow CrowdStrike's advisory.
  • CrowdStrike Laroux Malware Cleanup Tool: The vendor advisory lists 1.3.65.0 and earlier as affected, with 1.4.70.0 as the hotfixed build. The normalized record encodes 1.0.20 through versions less than 1.4.70.0 as affected. The advisory does not separately explain versions between 1.3.65.0 and 1.4.70.0, so the vendor's classification should take precedence for those versions.
  • The Falcon sensor for Mac, Linux, and Legacy Systems is identified by the vendor as not affected.

Technical details

The weakness is a CWE-367 time-of-check time-of-use race condition in the feature that processes and removes malicious macros from Microsoft Office files. When the Microsoft Office File Malicious Macro Removal host prevention policy is enabled, an actor with an unprivileged local context may reach an arbitrary file write to protected locations. The public advisory does not identify the file paths, function, API, race window, or payload involved, so those implementation details remain unknown. The supported reachability is local, requires low privileges, and does not require user interaction. The Laroux Malware Cleanup Tool is also affected because it is based on the same feature.

Exploitability

The attack path is local rather than network reachable, and it requires an attacker to have low-privileged access on the Windows system. The supplied record describes low attack complexity and no user interaction, but the attacker must still be able to execute in a local unprivileged context. The vulnerability exists only when the Microsoft Office File Malicious Macro Removal policy is enabled. CrowdStrike reports no indication of exploitation in the wild and says its threat hunting and intelligence team is continuing to monitor for abuse. The supplied record does not identify a public exploit; that does not prove that activity outside available visibility is impossible or absent.

Technical impact

The flaw may turn low-privileged local execution into the ability to write a file to a protected location, with possible local privilege escalation as a consequence. The record marks the scope as changed, so potential effects may cross the vulnerable sensor's immediate security boundary. A successful exploitation could affect system confidentiality, integrity, or availability, but the advisory does not identify the exact target file, the post-write execution mechanism, or the outcome in every configuration. The issue is not described as causing a sensor performance impact.

Business impact

An attacker who already has low-privileged local access may be able to write a file into a protected location. If the written content is subsequently used by a higher-privileged component, local privilege escalation is a possible consequence, but the advisory does not publish a complete exploit chain and the result should not be assumed for every configuration. The record describes potential effects on confidentiality, integrity, and availability, with a scope that may extend beyond the vulnerable component's immediate security boundary. CrowdStrike states that no direct or indirect sensor performance impact is expected and that none was seen in testing.

Remediation

  1. Upgrade Falcon sensor for Windows on each affected branch to the exact hotfixed build listed in affected_summary. Do not infer that a parallel or later branch is fixed unless the vendor guidance covers that branch.
  2. For 7.33, 7.31, and earlier unsupported versions, upgrade the system to a supported hotfixed Falcon sensor release instead of waiting for a fix to the obsolete branch.
  3. Replace affected Laroux Malware Cleanup Tool installations with 1.4.70.0 as directed by CrowdStrike. Where the normalized record and the advisory describe different lower boundaries, treat the installation as potentially affected until the vendor classification is verified.
  4. If Microsoft Office File Malicious Macro Removal was disabled as a temporary mitigation, CrowdStrike recommends re-enabling the policy after the systems have been upgraded to a fixed version.
  5. Verify the result through endpoint inventory, the actual installed build, and the policy state. The advisory does not provide another long-term mitigation or a recovery procedure for unsupported branches.

Detection

  1. Inventory Windows hosts running Falcon sensor and record the installed build, then compare it with the hotfixed builds in affected_summary.
  2. Review host prevention policies to determine whether Microsoft Office File Malicious Macro Removal is enabled.
  3. Separately identify systems running Falcon sensor on Windows 7 or Windows Server 2008 R2 because the applicable supported branch has a platform-specific condition.
  4. Inventory Laroux Malware Cleanup Tool deployments and confirm that affected versions have been replaced with the hotfixed build.
  5. Recheck endpoint inventory after updating to verify that the actual installed build changed. CrowdStrike does not provide a specific IOC or log signature in the advisory, so the absence of related log evidence must not be treated as proof that a system is safe.
Sources (8)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan