Time-of-check Time-of-use (TOCTOU) Race Condition in Falcon Sensor for Windows and Laroux Malware Cleanup Tool - CVE-2026-40058

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Falcon Sensor for Windows and Laroux Malware Cleanup Tool - CVE-2026-40058

Published: September 15, 2026


Vulnerability identifier: #VU150098
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40058
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check time-of-use race condition in the Office Macro Removal feature when removing malicious macros from Office files. A local user can exploit the race condition to write arbitrary files to protected locations to escalate privileges.

The issue only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled.


Affected software

Falcon Sensor for Windows
Laroux Malware Cleanup Tool

How to mitigate CVE-2026-40058

Install security update from vendor's website.

Falcon Sensor for Windows - addressed in versions 7.16.18644, 7.32.20410, 7.34.20613, 7.35.20712, 7.36.20807, 7.37.20912, 7.38.21007, 7.39.21113, 7.40.21309, 8.10.21408
Laroux Malware Cleanup Tool - update to 1.4.70.0

External References

Related Security Bulletins