What does Crowdstrike have to do with Microsoft Windows PCs crashing worldwide?

NEW DELHI: Microsoft Windows PCs at airports, banks, health services, IT companies, and news outlets worldwide are crashing and showing the infamous Blue Screen of Death, causing machines to either shut down or restart automatically.
While some attribute the crashes to the ongoing Microsoft cloud service outage, the Blue Screen of Death is likely caused by a recent CrowdStrike Falcon update, a cybersecurity solution used by corporations, government agencies worldwide and media houses like Sky News, which was unable to broadcast for a while.
Based out of the US, CrowdStrike is a cybersecurity firm founded by former McAfee employee George Kurtz. The company primarily focuses on helping organisations manage their security and protecting sensitive data and systems with internet connectivity. In case you were wondering why the issue isn’t affecting personal Windows PCs, it is because CrowdStrike does not sell its solution to retail customers.
In a statement, CrowdStrike CEO George Kurtz acknowledged the issue and said that it is actively working to fix the problem and that a “single content update for Windows hosts” is causing the problem. He added that it is not a cyberattack and that the problem is currently limited to Windows while Mac and Linux users remain unaffected.
What exactly caused the crashes?
Recently, CrowdStrike released an update to Falcon, a software with high-level access to systems, which is causing systems to crash. Since the problem is rendering affected Windows machines unusable, it is almost impossible to release another update to resolve the issue. This means that systems affected by the problem will need to be manually updated.
While the company did not explain why or how it pushed the buggy update, it did share a workaround that will help you fix your Windows PC in case it is crashing constantly. However, it needs to be manually applied to every system, which will be a time-consuming process for large organisations with thousands of PCs.
Omer Grossman, the Chief Information Officer (CIO) at CyberArk said that “the damage to business processes at the global level is dramatic. The glitch is due to a software update of CrowdStrike’s EDR product. This is a product that runs with high privileges that protects endpoints. A malfunction in this can, as we are seeing in the current incident, cause the operating system to crash.”
To fix the BSOD caused by CrowdStrike’s latest Falcon update, boot your Windows PC into Safe Mode, launch File Explorer and navigate to “C:\Windows\System32\drivers\CrowdStrike”. Now, find and delete the file named “C-00000291*.sys” and reboot.
For those wondering, blue screens are triggered when the operating system calls “KeBugCheckAPI”, which is equivalent to a fire alarm and is used as a last resort due to the lack of any other safe options. While there are various reasons behind the Blue Screen of Death, Microsoft says it is usually caused by faulty hardware or buggy software.
Agencies

Leave a Reply

Your email address will not be published.