CVE-2022-2841 is a missing authorization vulnerability affecting the uninstallation handler in CrowdStrike Falcon versions 6.31.14505.0, 6.42.15610, and 6.44.15806. This vulnerability, rated as LOW severity with a CVSS score of 2.7, allows a remote attacker with high privileges to uninstall the agent without requiring an installation token, leading to a loss of integrity (I:L). While not listed in CISA's KEV catalog, a public exploit (EDB-51146) exists, and the vulnerability has garnered some community discussion and media coverage, indicating awareness. Organizations are advised to upgrade to versions 6.40.15409, 6.42.15611, or 6.44.15807 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.31.14505.0CPE matchmatch criteria | cpe:2.3:a:crowdstrike:falcon:6.31.14505.0:*:*:*:*:*:*:* | ||
6.42.15610CPE matchmatch criteria | cpe:2.3:a:crowdstrike:falcon:6.42.15610:*:*:*:*:*:*:* | ||
6.44.15806CPE matchmatch criteria | cpe:2.3:a:crowdstrike:falcon:6.44.15806:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.