Is there a fatal windows update that has just dropped?
Edit - is CrowdStrike - thanks SirHumphreyAppleby
|
|
Work around steps for anyone that needs them
Do surveys for Beer money (referral link) - Octopus Group
Link for buying beer (not affiliated, just like beer) - Good George
Technical Details
On Windows systems, Channel Files reside in the following directory:
C:\Windows\System32\drivers\CrowdStrike\
and have a file name that starts with “C-”. Each channel file is assigned a number as a unique identifier. The impacted Channel File in this event is 291 and will have a filename that starts with “C-00000291-” and ends with a .sys extension. Although Channel Files end with the SYS extension, they are not kernel drivers.
Channel File 291 controls how Falcon evaluates named pipe1 execution on Windows systems. Named pipes are used for normal, interprocess or intersystem communication in Windows.
The update that occurred at 04:09 UTC was designed to target newly observed, malicious named pipes being used by common C2 frameworks in cyberattacks. The configuration update triggered a logic error that resulted in an operating system crash
Some resources:
Helping our customers through the CrowdStrike outage - The Official Microsoft Blog
Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19.pdf (crowdstrike.com)
Recover AWS resources affected by the CrowdStrike Falcon agent | AWS re:Post (repost.aws)
Technical Details: Falcon Update for Windows Hosts | CrowdStrike
Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies
Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.
|
|