CVE-2025-42706 describes a logic error in the Falcon sensor for Windows that allows an attacker with prior code execution to delete arbitrary files. This vulnerability specifically impacts Falcon sensor for Windows versions prior to 7.24 and all Long Term Visibility (LTV) sensors, while Mac, Linux, and Legacy Systems sensors are unaffected. Rated Medium (CVSS 6.5), the vulnerability has a local attack vector with low complexity, potentially leading to high availability impact. There is currently no evidence of in-the-wild exploitation, no public exploit code, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CrowdStrike | Falcon Sensor For Windows | >= 7.16, < 7.16.18637CNA affecteddefault unknown | |
| CrowdStrike | Falcon Sensor For Windows | >= 7.24, < 7.24.19608, >= 7.25, < 7.25.19707, >= 7.26, < 7.26.19813, >= 7.27, < 7.27.19909, >= 7.28, < 7.28.20008CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.