What happened
An identified vulnerability in the CrowdStrike Falcon sensor for Windows has been addressed through a security update. This flaw manifests only under specific configurations where the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled, and deployments are protected with the Cloud Anti-malware for Microsoft Office Files settings. The vulnerability enables an attacker with local access and low privileges to perform arbitrary file writes to protected locations, potentially leading to local privilege escalation. The issue does not affect the Falcon sensor for Mac, Linux, or legacy systems. Additionally, the CrowdStrike Laroux Malware Cleanup Tool, which shares features with the Falcon sensor, is also affected, with updates made available to mitigate this vulnerability.
Who is affected
Organisations running affected versions of the CrowdStrike Falcon sensor for Windows, specifically versions 7.16, 7.32 LTS, and 7.34, are impacted. The vulnerability requires the attacker to already possess local access to the host and use a low-privileged account, with no action needed from other users. The vulnerability is considered high severity due to its potential for arbitrary file writes and privilege escalation, though mitigated by existing security protections and configuration settings.
Recommended actions
- Ensure that security configurations do not enable the Microsoft Office File Malicious Macro Removal Windows policy setting unless necessary, as this creates the condition for the vulnerability to be exploited.
- Update the CrowdStrike Falcon sensor for Windows to the latest available version, which addresses this vulnerability. Updates for the Falcon sensor version 7.16, 7.32 LTS, and 7.34 are available immediately.
- Apply updates for the CrowdStrike Laroux Malware Cleanup Tool, which is also affected.
- Maintain strong privilege hygiene on endpoints, including restricting low-privileged user access where possible.
- Implement endpoint monitoring to detect suspicious activities pertaining to file writes in protected locations.
Indicators of compromise
Currently, no specific indicators of compromise have been provided for this vulnerability.

