CrowdStrike Falcon Windows Sensor Vulnerability Let Attackers Execute Code and Delete Files on Host
CrowdStrike has announced the identification and remediation of two medium-severity vulnerabilities in its Falcon sensor for Windows. These vulnerabilities, labeled as CVE-2025-42701 and CVE-2025-42706, could enable an attacker with code execution…
CrowdStrike has announced the identification and remediation of two medium-severity vulnerabilities in its Falcon sensor for Windows. These vulnerabilities, labeled as CVE-2025-42701 and CVE-2025-42706, could enable an attacker with code execution capabilities on a target system to delete arbitrary files.
The first vulnerability, CVE-2025-42701, is a Time-of-check Time-of-use (TOCTOU) race condition, categorized under CWE-367, with a CVSS 3.1 score of 5.6 (Medium). The second, CVE-2025-42706, is a logic error related to origin validation (CWE-346) and has a CVSS 3.1 score of 6.5 (Medium).
These vulnerabilities could allow threat actors to escalate their impact on a compromised system by deleting files, potentially causing significant issues with system stability and functionality, including disruptions to security monitoring.
The vulnerabilities affect CrowdStrike Falcon sensor for Windows versions 7.28 and earlier, specifically builds up to 7.28.20006, 7.27.19907, 7.26.19811, 7.25.19706, and 7.24.19607. Additionally, version 7.16.18635 and earlier for Windows 7 and Windows Server 2008 R2 systems are impacted. These issues do not affect Falcon sensors for macOS and Linux.
CrowdStrike has released updates to address these vulnerabilities. The latest version, 7.29, resolves these issues. Hotfixes are also available for earlier versions: 7.28 (7.28.20008), 7.27 (7.27.19909), 7.26 (7.26.19813), 7.25 (7.25.19707), and 7.24 (7.24.19608). A specific hotfix, 7.16.18637, is available for Windows 7 and 2008 R2 systems. Customers are advised to upgrade all affected systems to a patched version.
Affected Version Patched Version
CrowdStrike has announced the identification and remediation of two medium-severity vulnerabilities in its Falcon sensor for Windows.
7.28.20006 7.28.20008 and later
7.27.19907 7.27.19909
7.26.19811 & 7.26.19809 7.26.19813
7.25.19706 7.25.19707
7.24.19607 and earlier 7.24.19608
7.16.18635 and earlier (WIN7/2008 R2 only) 7.16.18637 (WIN7/2008 R2 only)
CrowdStrike identified these vulnerabilities internally through security management and its bug bounty program. The company is actively monitoring for exploitation attempts and has not detected any such activities to date. The simultaneous release of vulnerability details and patches aims to equip defenders with the necessary tools for remediation.
Customers are also provided with a query to identify impacted hosts, facilitating a more efficient remediation process. For further details, refer to the official advisory .
Based on reporting by Cyber Security News.
