CrowdStrike Falcon Products Man-in-the-Middle Vulnerability via Improper TLS Certificate Validation

Vulnerability

A validation logic error has been identified in CrowdStrike Falcon Sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor. This error allows the TLS connection routine to improperly process server certificate validation, potentially enabling an attacker to conduct a man-in-the-middle (MiTM) attack. The vulnerability affects all versions prior to 7.21, excluding hotfix builds for supported sensor versions. Windows and Mac sensors are not affected.

Impact

Exploitation could lead to a man-in-the-middle attack, allowing an attacker to intercept and potentially alter communications between the Falcon sensor and the CrowdStrike cloud.

Remediation

Users should upgrade to Falcon Sensor for Linux, Falcon Kubernetes Admission Controller, or Falcon Container Sensor versions 7.21 and later. Hotfixes are also available for certain earlier versions. For detailed instructions, refer to the CrowdStrike support portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
1.3
exploitability
4.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.