SB2026091583 - Privilege escalation in CrowdStrike Falcon Sensor for Windows
Published: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-40058)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in the Office Macro Removal feature when removing malicious macros from Office files. A local user can exploit the race condition to write arbitrary files to protected locations to escalate privileges.
The issue only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled.
Remediation
Install update from vendor's website.