July 21st, 2024

Technical Details: Falcon Update for Windows Hosts

CrowdStrike issued a Windows sensor update causing crashes on July 19, 2024, fixed by 05:27 UTC. Customers using affected versions may have experienced issues. Linux and macOS systems were unaffected. CrowdStrike is investigating and providing remediation guidance.

Read original articleLink Icon
Technical Details: Falcon Update for Windows Hosts

CrowdStrike released a sensor configuration update for Windows systems on July 19, 2024, which led to a logic error causing system crashes and blue screens on impacted systems. The issue was resolved by 05:27 UTC the same day. Customers using Falcon sensor for Windows version 7.11 and above between 04:09 and 05:27 UTC may have been affected. The update targeted malicious named pipes used in cyberattacks, triggering the error. CrowdStrike corrected the logic error in Channel File 291 and continues to protect against named pipe abuse. Systems running Linux or macOS were not impacted. CrowdStrike is conducting a root cause analysis to strengthen processes. Customers can find remediation recommendations on their blog or Support Portal. Systems not impacted will continue to operate normally. This incident was not related to a cyberattack and does not involve null bytes in Channel File 291.

Related

Latest Crowdstrike Update Causes Blue Screen of Death on Microsoft Windows

Latest Crowdstrike Update Causes Blue Screen of Death on Microsoft Windows

Crowdstrike update causes BSOD on Windows, affecting many users with various sensor versions. Company investigating, advises waiting for official Technical Alert for details and workarounds. Users urged to monitor forum for updates.

Cybersecurity platform Crowdstrike down worldwide, users logged out of systems

Cybersecurity platform Crowdstrike down worldwide, users logged out of systems

CrowdStrike, a cybersecurity platform, faced a global outage affecting users in countries like India, Japan, Canada, and Australia due to a technical error in its Falcon product. Users encountered disruptions, including BSOD errors. CrowdStrike is actively working on a fix.

CrowdStrike code update bricking PCs around the world

CrowdStrike code update bricking PCs around the world

CrowdStrike's Falcon Sensor update triggers Windows crashes with Blue Screen of Death due to csagent.sys file issues. Workaround involves file deletion in Safe Mode. CrowdStrike is addressing the problem.

Crowdstrike – Statement on Falcon Content Update for Windows Hosts

Crowdstrike – Statement on Falcon Content Update for Windows Hosts

CrowdStrike addresses a Windows host content update defect, reassuring Mac and Linux hosts are safe. The issue, not a cyberattack, is resolved. Impacted customers receive support and guidance for recovery.

Technical Details on Today's Outage

Technical Details on Today's Outage

CrowdStrike faced a temporary outage on July 19, 2024, caused by a sensor update on Windows systems, not a cyberattack. The issue affected some users but was fixed by 05:27 UTC. Systems using Falcon sensor for Windows version 7.11+ between 04:09-05:27 UTC might have been impacted due to a logic error from an update targeting malicious named pipes. Linux and macOS systems were unaffected. CrowdStrike is investigating the root cause and supporting affected customers.

Link Icon 3 comments
By @thedataplumber - 6 months
There is absolutely no excuse for the communication strategy of crowdstrike.

The only information they give out is "we were not hacked, we know what the priblem is but we won't tell you" Why not tell us the current state of the investigation? They obviously didn't have a good ci/cd process for deploying changes to channel files and they should at the very least describe the release process, as far as they know how it, for channel updates are tested before release (if at all).

By @teyc - 6 months
“Not cyberattack”. How about friendly fire.
By @mrjin - 6 months
Wow, even better, so they are blocking named pipes by names.