Get a Demo
Under Attack?
An illustration of Earth at the center with six pink icons connected to it by dotted lines: a computer, a factory, an airplane, a warning symbol, a stethoscope, and a satellite dish. The word upwind is in the top left corner.

What Happened with the CrowdStrike Update?

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur July 19, 2024

A recent CrowdStrike Falcon sensor update has caused a massive Windows Blue Screen of Death (BSOD) outage. CrowdStrike offers endpoint protection and other services that are used on a widespread scale worldwide, and this sensor update issue is causing global issues.

Impact

There are widespread reports of BSOD error on Windows hosts, all of which are associated with multiple versions of CrowdStrike sensors. This update is believed to have sent servers, desktops, laptops and computer endpoints into a spiral of reboots that are commonly referred to as the “blue screen of death,” wilth the error message, “DRIVEN_OVERRAN_STACK_BUFFER.”

Screenshot-2024-07-19-at-8.00.24%E2%80%AFAM-1024x689

Details of the CrowdStrike Update

Symptoms of the Windows crash include hosts experiencing a bugcheck message or the Blue Screen of Death error, both of which are related to CrowdStrike Falcon Sensor update. CrowdStrike has indicated that channel file C-00000291*.sys with timestamp of 0409 UTC is the problematic version, and that channel file C-00000291*.sys with timestamp of 0527 UTC (July 19) or later is the reverted (good) version. 

CrowdStrike has also indicated that  Windows hosts that are brought online after 0527 UTC, Hosts running Windows 7/2008 R2, and Mac- or Linux-based hosts will not be impacted.

Current Actions for Remediation

Workaround Steps for individual hosts:

  1. Reboot the host to give it an opportunity to download the reverted channel file. If the host crashes again, then:
    1. Boot Windows into Safe Mode or the Windows Recovery Environment
      • NOTE: Putting the host on a wired network (as opposed to WiFi) and using Safe Mode with Networking can help remediation.
  2. Navigate to the %WINDIR%\System32\drivers\CrowdStrike directory
  3. Locate the file matching C-00000291*.sys and delete it.
  4. Boot the host normally.
    • Note: Bitlocker-encrypted hosts may require a recovery key.

Workaround Steps for public cloud or similar environment including virtual:

Option 1:

  1. ​​​​​​​Detach the operating system disk volume from the impacted virtual server
  2. Create a snapshot or backup of the disk volume before proceeding further as a precaution against unintended changes
  3. Attach/mount the volume to to a new virtual server
  4. Navigate to the %WINDIR%\System32\drivers\CrowdStrike directory
  5. Locate the file matching C-00000291*.sys and delete it.
  6. Detach the volume from the new virtual server
  7. Reattach the fixed volume to the impacted virtual server

Option 2:

  • ​​​​​​​Roll back to a snapshot before 0409 UTC.

Get Assistance 

As many are affected worldwide, we understand that you might be impacted by the recent CrowdStrike agent issue and are working to fix it. We are here to help you. Upwind has put together a dedicated team available 24/7 to provide you with the support needed to get you back up and running. Please do not hesitate to reach out to us at any time.

For Upwind customers, please reach out to us in the console chat. For all others, please fill out the following form or email us at [email protected] and will reach out to you within minutes of submission.

Contents

Further Reading

OpenAI Breach

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story

Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…
upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS