Security News > 2024 > July > Faulty CrowdStrike update takes out Windows machines worldwide
Houndreds of housands and possibly millions of Windows computers and servers worldwide have been made inoperable by a faulty update of Crowdstrike Falcon Sensors, and the outage affected transport, broadcast, financial, retail and other organizations in Europe, Australia, the US and elsewhere.
What initially seemed like it might be a Microsoft problem is now confirmed to have been created by Crowdstrike, i.e., its endpoint security agent.
Locating the file matching "C-00000291*.sys" and deleting it, then4.
In many cases this will have to be a manual intervention that has to be performed via a local admin account, and it will take a while at companies with huge fleets of Windows PC workstations to restore them - and on a Friday, too.
Crowdstrike is surely analyzing the "Bad" update to see what happened, and security researchers are trying to do the same.
"The.sys files causing the issue are channel update files, they cause the top level CS driver to crash as they're invalidly formatted. It's unclear how/why Crowdstrike delivered the files and I'd pause all Crowdstrikes updates temporarily until they can explain," security researcher Kevin Beaumont noted.
News URL
https://www.helpnetsecurity.com/2024/07/19/crowdstrike-outage/
Related news
- Windows 11 Task Manager says no apps are active after preview update (source)
- Microsoft says recent Windows 11 updates break SSH connections (source)
- Windows 11 KB5046617 and KB5046633 cumulative updates released (source)
- Windows 10 KB5046613 update released with fixes for printer bugs (source)
- Microsoft pulls WinAppSDK update breaking Windows 10 app uninstalls (source)
- Windows 11 KB5046740 update released with 14 changes and fixes (source)
- Windows 10 KB5046714 update fixes bug preventing app uninstalls (source)
- Windows 11 24H2 update blocked on PCs with Assassin's Creed, Star Wars Outlaws (source)
- Windows 11 KB5048667 & KB5048685 cumulative updates released (source)
- Windows 10 KB5048652 update fixes new motherboard activation bug (source)