SB2026091583 - Privilege escalation in CrowdStrike Falcon Sensor for Windows



SB2026091583 - Privilege escalation in CrowdStrike Falcon Sensor for Windows

Published: September 15, 2026

Security Bulletin ID SB2026091583
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-40058)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check time-of-use race condition in the Office Macro Removal feature when removing malicious macros from Office files. A local user can exploit the race condition to write arbitrary files to protected locations to escalate privileges.

The issue only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled.


Remediation

Install update from vendor's website.