- Description
- CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above. CrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. Windows and Mac sensors are not affected by this.
- Source
- 13ddcd98-6f4a-40a8-8e24-29ca0aee4661
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- 13ddcd98-6f4a-40a8-8e24-29ca0aee4661
- CWE-296
- Hype score
- Not currently trending
Threat Alert: Critical Vulnerability in Crowdstrike Falcon Sensor for Linux Enables TLS MiTM E CVE-2025-1146 Severity: 🔴 High Maturity: 🧨 Trending Learn more: https://t.co/115hpU4V0X #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
19 Feb 2025
13 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Warning: #CVE-2025-1146 affects multiple versions of #CrowdStrike Falcon Sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor, enabling potential Man-in-the-Middle attacks. Patch now! Advisory: https://t.co/ZlmL1Qz7N9 #patch #patch
@CCBalert
17 Feb 2025
19 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Atenção, profissionais de TI! Uma vulnerabilidade crítica (CVE-2025-1146) no CrowdStrike Falcon Sensor pode deixar seus dados expostos. A atualização é essencial! Sabia que a CrowdStrike já adotou diversas medidas de segurança para mitigar riscos? Mantenha-se protegido!
@IncursioHack
16 Feb 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CrowdStrike has disclosed a high-severity vulnerability in its Falcon Sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor. The vulnerability, identified as CVE-2025-1146. #เราต้องการฝ้ายโยโกะ #ElonMusk #Trump #CyberSecurity #AI #provadolíder htt
@techaniruddh
14 Feb 2025
120 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
CrowdStrike has disclosed a vulnerability (CVE-2025-1146) in its Falcon Sensor for Linux, its Falcon Kubernetes Admission Controller, and its Falcon Container Sensor. #cybersecurity https://t.co/4vCnuMxD9B
@cybertzar
14 Feb 2025
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1146 impacts selected CrowdStrike Falcon Sensors #Crowdstrike #CVE-2025-1146 https://t.co/XBlAwv1OW6
@pravin_karthik
13 Feb 2025
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 A critical vulnerability (CVE-2025-1146) in CrowdStrike's Falcon Sensor for Linux could expose systems to TLS MiTM attacks. Patching is essential for security. Affected versions: <7.21. #CrowdStrike #Linux #USA link: https://t.co/yxQHHxmk37 https://t.co/DP95hBBAQv
@TweetThreatNews
13 Feb 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CrowdStrike Addresses High-Severity TLS Vulnerability in Falcon Sensor for Linux (CVE-2025-1146) https://t.co/pyuwi4voFX
@Dinosn
13 Feb 2025
2893 Impressions
17 Retweets
32 Likes
4 Bookmarks
0 Replies
0 Quotes
CVE-2025-1146 CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a… https://t.co/DDlpfKQoW0
@CVEnew
12 Feb 2025
210 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes