Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


MadEngineer

4591 posts

Uber Geek
+1 received by user: 2570

Trusted

#315467 19-Jul-2024 17:08
Send private message

Is there a fatal windows update that has just dropped?


Edit - is CrowdStrike - thanks SirHumphreyAppleby




You're not on Atlantis anymore, Duncan Idaho.

View this topic in a long page with up to 500 replies per page Create new topic

This is a filtered page: currently showing replies marked as answers. Click here to see full discussion.

gjm

gjm
810 posts

Ultimate Geek
+1 received by user: 122


  #3261549 19-Jul-2024 18:33
Send private message

Work around steps for anyone that needs them

 

     

  1. Boot Windows into Safe Mode or the Windows Recovery Environment
  2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
  3. Locate the file matching “C-00000291*.sys”, and delete it.
  4. Boot the host normally. 




Do surveys for Beer money (referral link) - Octopus Group 

 

Link for buying beer (not affiliated, just like beer) - Good George




clinty
1201 posts

Uber Geek
+1 received by user: 402

Lifetime subscriber

  #3261954 21-Jul-2024 05:46
Send private message

Crowd strike have blogged the technical details of what happened

https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/




Technical Details
On Windows systems, Channel Files reside in the following directory:

C:\Windows\System32\drivers\CrowdStrike\

and have a file name that starts with “C-”. Each channel file is assigned a number as a unique identifier. The impacted Channel File in this event is 291 and will have a filename that starts with “C-00000291-” and ends with a .sys extension. Although Channel Files end with the SYS extension, they are not kernel drivers.

Channel File 291 controls how Falcon evaluates named pipe1 execution on Windows systems. Named pipes are used for normal, interprocess or intersystem communication in Windows.

The update that occurred at 04:09 UTC was designed to target newly observed, malicious named pipes being used by common C2 frameworks in cyberattacks. The configuration update triggered a logic error that resulted in an operating system crash


Clint

View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.