CVE-2022-2841

LOW

CrowdStrike Falcon <6.31.14505.0/6.42.15610/6.44.15806 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.40.15409, 6.42.15611 and 6.44.15807 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-206880.

Exploits (1)

exploitdb WORKING POC
by Fortunato Lodari · powershelllocalwindows
https://www.exploit-db.com/exploits/51146

Scores

CVSS v3 2.7
EPSS 0.1037
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
crowdstrike/falcon 6.31.14505.0
crowdstrike/falcon 6.42.15610
crowdstrike/falcon 6.44.15806
Published Aug 22, 2022
Tracked Since Feb 18, 2026