Skip to main content

CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash

  • August 6, 2024
  • 1 reply
  • 11 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

CrowdStrike says the Falcon sensor crash that blue-screened Windows machines was caused by a “confluence” of vulnerabilities and testing gaps.

 

August 6, 2024 By Ryan Naraine

 

CrowdStrike Root Cause Analysis

Embattled cybersecurity vendor CrowdStrike on Tuesday released a root cause analysis detailing the technical mishap behind a software update crash that crippled Windows systems globally and blamed the incident on a confluence of security vulnerabilities and process gaps.

The new CrowdStrike root cause analysis documents a combination of factors the  Falcon EDR sensor crash  — a mismatch between inputs validated by a Content Validator and those provided to a Content Interpreter, an out-of-bounds read issue in the Content Interpreter, and the absence of a specific test — and a vow to work with Microsoft on secure and reliable access to the Windows kernel.

“Sensors that received the new version of Channel File 291 carrying the problematic content were exposed to a latent out-of-bounds read issue in the Content Interpreter. At the next IPC notification from the operating system, the new IPC Template Instances were evaluated, specifying a comparison against the 21st input value. The Content Interpreter expected only 20 values,” CrowdStrike explained.

 

>>Full Article<<

1 reply

TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • August 6, 2024

Embattled cybersecurity vendor CrowdStrike 😶