PT-2022-4350 · Crowdstrike · Crowdstrike Falcon

Max Moser

+1

·

Published

2022-08-22

·

Updated

2024-05-17

·

CVE-2022-2841

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions CrowdStrike Falcon versions 6.31.14505.0 through 6.44.15806
Description A vulnerability was found in the Uninstallation Handler component of CrowdStrike Falcon, related to incorrect implementation of the uninstall protection function. This leads to missing authorization, allowing an attacker to remove the software without a valid token. The manipulation can be launched remotely.
Recommendations For versions 6.31.14505.0, 6.42.15610, and 6.44.15806, upgrade to version 6.40.15409, 6.42.15611, or 6.44.15807 to address this issue. As a temporary workaround, consider disabling the Uninstallation Handler component until a patch is available. Restrict access to the Uninstallation Protection function to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-05210
CVE-2022-2841

Affected Products

Crowdstrike Falcon