CVE-2022-2841
CrowdStrike Falcon Sensor vulnerability analysis and mitigation

Overview

A vulnerability was discovered in CrowdStrike Falcon versions 6.31.14505.0/6.42.15610/6.44.15806, identified as CVE-2022-2841. The vulnerability affects the Uninstallation Handler component and was discovered in April 2022 by researchers at modzero AG. The issue relates to insufficient control flow management in the uninstallation protection mechanism of the CrowdStrike Falcon sensor (Modzero Advisory).

Technical details

The vulnerability is classified as CWE-691: Insufficient Control Flow Management, allowing bypass of the uninstall protection feature. The issue occurs in the Microsoft Installer (MSI) implementation, where the MSI fails open instead of failing closed when a Custom Action terminates without returning. This behavior allows circumvention of the token verification process during uninstallation (SecurityWeek, VulDB).

Impact

When exploited, the vulnerability allows an attacker with administrative privileges to bypass the uninstall protection mechanism and remove the CrowdStrike Falcon sensor from the device without proper authorization. This effectively removes the device's EDR and AV protection, leaving the CrowdStrike administrator unaware of potential attacks on the now unprotected endpoint (Modzero Advisory).

Mitigation and workarounds

The vulnerability can be addressed by upgrading to CrowdStrike Falcon versions 6.40.15409, 6.42.15611, or 6.44.15807. CrowdStrike has also implemented additional security measures to flag potentially malicious uninstallation attempts (VulDB).

Community reactions

The disclosure process of this vulnerability generated significant attention due to communication challenges between modzero AG and CrowdStrike. The researchers expressed frustration with CrowdStrike's insistence on using their bug bounty program and requiring NDAs, leading to a public disclosure of the vulnerability (SecurityWeek).

Additional resources


SourceThis report was generated using AI

Related CrowdStrike Falcon Sensor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-1146HIGH8.1
  • CrowdStrike Falcon SensorCrowdStrike Falcon Sensor
  • cpe:2.3:a:crowdstrike:falcon
NoYesFeb 12, 2025
CVE-2022-2841LOW2.7
  • CrowdStrike Falcon SensorCrowdStrike Falcon Sensor
  • cpe:2.3:a:crowdstrike:falcon
NoYesAug 22, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management