CrowdStrike Windows Outage—What Happened And What To Do Next (2024)

A CrowdStrike update is breaking computers running Windows, causing them to crash and display the blue screen of death. Across industries, companies around the world haven’t been able to reboot, according to reports. Firms affected by the outage include Sky News, which has been unable to broadcast.

Concerned users have taken to forums such as Reddit to report the issue, with one user saying: “Wow, stuck in a boot loop, and entire org taken out.”

So if you got into work this morning and were met by, frankly, carnage, know that you are not alone. Here’s what happened and what to do next.

What Happened

As you might have gathered, an issue with CrowdStrike cybersecurity software is causing the widespread global issue. Engineers at the company said they are working on the issue, which affects its Falcon Sensor product. CrowdStrike calls Falcon “the CrowdStrike platform purpose-built to stop breaches via a unified set of cloud-delivered technologies that prevent all types of attacks—including malware and much more.”

The IT outage has affected airports, businesses and broadcasters, according to the Sky News website. Planes have been grounded in the U.S., trains in the U.K. are impacted, as well as boarding scanners at Edinburgh airport in Scotland.

MORE FOR YOU

Jake Paul Vs. Mike Perry Results: KO Highlight And Reaction
Viral ‘KO Of The Year’ Steals The Show At Jake Paul-Mike Perry Event
2024 Election: The Elephant In The Room -Kamala Harris

Microsoft said it is taking “mitigation actions” after service issues it said started at about 6 p.m. Eastern Time. The company says it is investigating issues with cloud services in the U.S. and “an issue impacting several of its apps and services,” Sky News reported.

“We are aware of a scenario in which customers experience issues with their machines causing a bug check (blue screen) due to a recent CrowdStrike update,” a Microsoft spokesperson said. “We recommend customers to follow guidance provided by CrowdStrike.”

While initial reports focused on a dodgy update, a user named Brody, who is director of CrowdStrike Overwatch, posted on X (formerly Twitter) that it is “a faulty channel file, so not quite an update.”

There is a workaround, he added.

1. Boot Windows into Safe Mode or WRE.

2. Go to C:\Windows\System32\drivers\CrowdStrike

3. Locate and delete file matching "C-00000291*.sys"

4. Boot normally.

At 5:45 a.m. ET, CrowdStrike CEO George Kurtz posted on X, confirming the issue is not a cyberattack and was caused by a botched update.

“CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack,” Kurz wrote, adding that the issue has been “identified, isolated and a fix has been deployed.”

“We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website,” he added. “We further recommend organizations ensure they’re communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers.”

What To Do

It’s not easy to say what to do next. While there is a workaround, it’s not scalable, as it would need to be applied manually, system by system. In a large company, this could could take hours or more to get back up and running.

By its nature, the issue is going to be very hard to resolve once systems are in a reboot loop, says Adam Harrison, managing director at FTI Cybersecurity. “Manual fixes are going to take time for system admins to apply: CrowdStrike can't push a new update remotely to fix. It's going to need manual intervention on each system.”

You might be lucky and be able to roll back to known good states, but the majority won't have anything that supports doing that, says Harrison. “The fix itself is quick to perform, but when you scale that up to thousands of servers and/or thousands of workstations, it's going to be a bad day in the office for lots of folks.”

It’s also going to be a bad day for CrowdStrike. What can the firm do to help people?

“They can only communicate that fix as quickly and widely as they can,” says Harrison. “My assumption would be that the update is already down, so any systems which hadn't updated for any reasons shouldn't still get pushed a bad update.”

Ian Thornton-Trump, CISO at Cyjax, says CrowdStrike “will certainly do their very best to pull the update and instruct the old agents not to update till they can get it sorted.”

However, he says, “what has been done can not be undone for those blue screen machines. If the machines can be booted in safe mode they may be able to issue an out of band update or patch. That’s time consuming—if the machines are critical, they might actually consider restoring from backup or a shadow copy (a built in MSFT recovery feature). Whatever path they have, they will try and fix as quickly as possible.”

CrowdStrike might be able to put a tool together that would apply the fix at the disk level, such as bootable media, says Harrison. “This would maybe help some people out who have thousands of systems to fix. It’s still not a solution that solves the problem fully remotely or at huge scale, but it could bring recovery times down.”

This is a breaking story. Keep your eyes peeled and check back to my Forbes page for updates.

CrowdStrike Windows Outage—What Happened And What To Do Next (2024)

FAQs

What is the CrowdStrike Windows issue? ›

He wrote, "CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed.

Why was CrowdStrike down? ›

Outage caused by CrowdStrike software update

CrowdStrike told customers early Friday the outages were caused by “a defect found in a single content update of its software on Microsoft Windows operating systems,” according to a post on X from CEO George Kurtz.

What did the CrowdStrike update do? ›

SAN FRANCISCO, July 19 (Reuters) - Security experts said CrowdStrike's (CRWD.O) , opens new tab routine update of its widely used cybersecurity software, which caused clients' computer systems to crash globally on Friday, apparently did not undergo adequate quality checks before it was deployed.

What is the CrowdStrike outage affecting? ›

What has been affected? The outage appeared to affect almost every major business sector in one way or another. Airports and flights across the world were severely delayed or canceled altogether, as the computers on which these services rely were disrupted by the issue.

How long did the CrowdStrike outage last? ›

The outage occured just after 2 pm AEST on Friday, with CrowdStrike finding a fix about an hour and half later. Prime Minister Anthony Albanese says governments across all levels acted swiftly and worked together cooperatively to minimise the disruption in Australia.

What was the cause of the IT outage? ›

The global outage stems from an update CrowdStrike made to its marquee cybersecurity platform, a cloud-based software product called Falcon.

What caused CrowdStrike to crash? ›

What happened? CrowdStrike, which sells security software designed to keep systems safe from external attacks, pushed a faulty "sensor configuration update" to the millions of PCs worldwide running its Falcon Sensor software.

Is CrowdStrike on all Windows? ›

We currently estimate that CrowdStrike's update affected 8.5 million Windows devices, or less than one percent of all Windows machines. While the percentage was small, the broad economic and societal impacts reflect the use of CrowdStrike by enterprises that run many critical services.

How many computers are affected by CrowdStrike? ›

Microsoft has estimated that the incident, which is being described as one of the worst IT outages in history, impacted 8.5m computers around the world.

What went wrong at CrowdStrike? ›

This configuration update triggered a logic error resulting in a system crash and blue screen (BSOD) on impacted systems," wrote Kurtz. The CEO claimed that the issue has been rectified, "The sensor configuration update that caused the system crash was remediated on Friday, July 19, 2024 05:27 UTC."

What was the reason behind Microsoft's outage? ›

Cause Of The Outage

In an update late Friday evening, CrowdStrike identified a “logic error” as the culprit in the Microsoft outage. The programming error was triggered by a sensor configuration update to Falcon.

How to fix CrowdStrike issue in Microsoft? ›

“The issue has been identified, isolated and a fix has been deployed.” Posting to Twitter/X, the director of Crowdstrike's threat hunting operations said the fix involves booting Windows into Safe Mode or the Windows Recovery Environment (Windows RE), deleting the file “C-00000291*.sys” and then restarting the machine.

What was the error in CrowdStrike? ›

In a blog post releasing technical details late Friday, CrowdStrike identified a “logic error” as the culprit in the Microsoft outage. The programming error was triggered by a sensor configuration update to Falcon, which is a frequent type of update.

What's the deal with CrowdStrike? ›

What is CrowdStrike? CrowdStrike is a U.S. cybersecurity company that provides software to companies around the world and across industries. It bills itself as being the globe's most advanced cloud-based security technology provider. “We stop breaches,” the cybersecurity company says on its website.

What does CrowdStrike window sensor do? ›

CrowdStrike installs a lightweight sensor on your machine that is less than 5MB and is completely invisible to the end user. Once CrowdStrike is installed, it actively scans for threats on your machine without having to manually run virus scans.

References

Top Articles
Latest Posts
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 5593

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.