CrowdStrike Fixed Arbitrary File Deletion Flaws in Falcon Sensor for Windows

Share:

CrowdStrike has released fixes for two security issues affecting the Falcon sensor for Windows. Both vulnerabilities require an attacker to have already established the ability to execute code on the host system. Successful exploitation could allow the adversary to delete arbitrary files , which could lead to stability or functionality issues with the Falcon sensor, other software, or the operating system itself.

Severity: Moderate

Vulnerability Details

1. CVE-2025-42701

CVSS Score: 5.6
Type: CWE-367 [Time-of-check Time-of-use (TOCTOU) Race Condition]
Description: A race condition in the Falcon Sensor for Windows allows an attacker with local code execution privileges to delete arbitrary files.

2.CVE-2025-42706

CVSS Score: 6.5
Type: CWE-346 [Origin Validation Error]
Description: A logic error in Falcon Sensor for Windows allows attackers to delete arbitrary files due to improper validation.

3.Exploitation of the Vulnerability:

Prerequisite: To exploit these issues, an adversary must have the prior ability to execute code on a host.
Potential Actions: Deletion of arbitrary system, application, or Falcon Sensor files.
Impact: May lead to loss of system stability, malfunction of endpoint security controls, or operational disruptions.
Current Status: CrowdStrike has no indication that these issues have been exploited in the wild and is actively monitoring for any signs of abuse.

Affected Products

Falcon sensor for Windows versions: 7.28.20006, 7.27.19907, 7.26.19811, 7.26.19809, 7.25.19706, 7.24.19607 and earlier, 7.16.18635 and earlier 7.16 builds (WIN7/2008 R2 only)

Recommendations

  1. The recommended action is for customers to upgrade Windows hosts running the affected sensor versions to a fixed version.
    The fixes are available in the following versions: 7.28.20008 and later, 7.27.19909, 7.26.19813, 7.25.19707, 7.24.19608, 7.16.18637 (WIN7/2008 R2 only)
  2. Customers can use CrowdStrike’s query on GitHub to look for Falcon Sensor for Windows versions that need to be hotfixed or updated to address CVE-2025-42701 and CVE-2025-42706.

Source:

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.