An update to CrowdStrike’s Falcon Sensor has caused widespread issues, rendering Windows machines inoperable.
CrowdStrike’s Response
CrowdStrike has acknowledged the issue. They issued an advisory, which is accessible only to customers, titled “Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19.”
An apparent screenshot of the advisory reads: “CrowdStrike is aware of reports of crashes on Windows hosts related to the Falcon Sensor. Symptoms include hosts experiencing a bugcheckblue screen error related to the Falcon Sensor.”
Workaround Suggested
Brody Nisbet, CrowdStrike’s chief threat hunter, confirmed the issue and provided a temporary workaround via X:
- Boot Windows into Safe Mode or Windows Recovery Environment (WRE).
- Navigate to
C:WindowsSystem32driversCrowdStrike. - Locate and delete files matching “C-00000291*.sys”.
- Boot normally.
Nisbet noted, “That workaround won’t help everyone though and I’ve no further actionable help to provide at the minute.”
Impact and Reactions
The Falcon Sensor, which is supposed to protect systems, is currently causing significant disruptions. Users have expressed frustration and concern, particularly those in organizations relying on Windows for critical services.
CrowdStrike’s engineers are actively working to resolve the issue. However, until a permanent fix is released, many systems remain at risk.
Ongoing Coverage
This is a developing story. The Register will continue to provide updates as new information becomes available.