CVE-2022-2841

LOW

CrowdStrike Falcon <6.31.14505.0/6.42.15610/6.44.15806 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-2841. PoCs published by Fortunato Lodari.

AI-analyzed exploit summary This PowerShell script exploits CVE-2022-2841 to uninstall CrowdStrike Falcon Agent without requiring an installation token by forcibly terminating the uninstaller process at a specific stage. It identifies the installed Falcon Agent via registry keys and triggers the uninstaller while monitoring and killing the msiexec process to bypass token validation.

Description

A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.40.15409, 6.42.15611 and 6.44.15807 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-206880.

Exploits (1)

exploitdb WORKING POC
by Fortunato Lodari · powershelllocalwindows
https://www.exploit-db.com/exploits/51146

This PowerShell script exploits CVE-2022-2841 to uninstall CrowdStrike Falcon Agent without requiring an installation token by forcibly terminating the uninstaller process at a specific stage. It identifies the installed Falcon Agent via registry keys and triggers the uninstaller while monitoring and killing the msiexec process to bypass token validation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: CrowdStrike Falcon Agent 6.44.15806
Auth required
Prerequisites: Local administrative access · CrowdStrike Falcon Agent installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory vdb-entry
https://vuldb.com/?id.206880
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.206880
Exploit, Third Party Advisory media-coverage
https://youtu.be/3If-Fqwx-4s

Scores

CVSS v3 2.7
EPSS 0.0367
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
crowdstrike/falcon 6.31.14505.0
crowdstrike/falcon 6.42.15610
crowdstrike/falcon 6.44.15806
Published Aug 22, 2022
Tracked Since Feb 18, 2026