CrowdStrike Falcon Windows Sensor Flaw Could Let Attackers Execute Code and Delete Files
CrowdStrike has identified two critical vulnerabilities affecting its Falcon sensor for Windows. These vulnerabilities could enable attackers to delete arbitrary files, potentially compromising system stability.
CrowdStrike has identified two critical vulnerabilities affecting its Falcon sensor for Windows. These vulnerabilities could enable attackers to delete arbitrary files, potentially compromising system stability.
The identified vulnerabilities are CVE-2025-42701 and CVE-2025-42706. Both require prior code execution capabilities on the target system.
CVE-2025-42701: A race condition vulnerability with a CVSS score of 5.6. CVE-2025-42706: A logic error with a CVSS score of 6.5.
These flaws could allow malicious actors to delete arbitrary files on affected Windows systems, potentially affecting the Falcon sensor or other critical software components, including the operating system.
The race condition issue is classified under CWE-367, while the logic error pertains to origin validation problems categorized as CWE-346. CrowdStrike discovered these vulnerabilities through its Bug Bounty program.
Only Windows-based Falcon sensors are affected. Mac, Linux, and Legacy Windows Systems are not impacted.
CVE ID Vulnerability Type CVSS Score Impact
CrowdStrike has identified two critical vulnerabilities affecting its Falcon sensor for Windows.
CVE-2025-42701 CrowdStrike Falcon Sensor for Windows Race Condition 5.6 (MEDIUM) File deletion capability with prior code execution
CVE-2025-42706 CrowdStrike Falcon Sensor for Windows Logic Error 6.5 (MEDIUM) File deletion capability with prior code execution
CrowdStrike has implemented patches across multiple sensor versions to address these vulnerabilities. The patches are available in Falcon sensor version 7.29 and hotfix releases for versions 7.24 through 7.28. Additionally, a specialized 7.16 hotfix is available for Windows 7 and 2008 R2 systems.
7.28.20006 7.27.19907 7.26.19811 7.25.19706 7.24.19607 and earlier builds 7.16.18635 and earlier 7.16 builds for Windows 7 and 2008 R2 environments
The corresponding patched versions include:
7.28.20008 and later 7.27.19909 7.26.19813 7.25.19707 7.24.19608 7.16.18637 for legacy Windows systems
The version 7.24 hotfix also updates the current Long-Term Visibility sensor for Windows IoT deployments.
CrowdStrike provides a GitHub query to help customers identify potentially impacted hosts within their environments. There is no evidence of active exploitation of these vulnerabilities in production environments. CrowdStrike's threat hunting and intelligence teams continue to monitor for potential abuse attempts.
The company advises customers to upgrade Windows hosts running affected sensor versions to the latest patched releases to maintain optimal security posture and prevent potential file deletion attacks. No performance impact is expected from the security updates, as testing has revealed no direct or indirect effects on sensor functionality.
For further details, visit the official CrowdStrike advisory .
Based on reporting by GBHackers.
