CVE Database
/

CVE-2025-42701

Back to search

CVE-2025-42701

Published: Oct 8, 2025

Modified: Oct 8, 2025

PUBLISHED

CVSS v3.1

5.6

MEDIUM

Description

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is no indication of exploitation of these issues in the wild. Our threat hunting and intelligence team are actively monitoring for exploitation and we maintain visibility into any such attempts. The Falcon sensor for Mac, the Falcon sensor for Linux and the Falcon sensor for Legacy Systems are not impacted by this. CrowdStrike was made aware of this issue through our HackerOne bug bounty program. It was discovered by Cong Cheng and responsibly disclosed.

VendorProductVersions

CrowdStrike

Falcon sensor for Windows

affected
7.28 - < 7.28.20008
affected
7.27 - < 7.27.19909
affected
7.26 - < 7.26.19813
affected
7.25 - < 7.25.19707
affected
7.24 - < 7.24.19608

CrowdStrike

Falcon sensor for Windows

affected
7.16 - < 7.16.18637

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now