Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools
ID: 7055e557-5305-5ba6-a0d3-72eef40b0031
STIX ID: report--7055e557-5305-5ba6-a0d3-72eef40b0031
Feed Name: The Register (Security)
Microsoft outlined best practices and new initiatives to improve reliability after the CrowdStrike Falcon driver update caused widespread Windows crashes, urging security vendors to minimize kernel-mode usage and move auxiliary functions like configuration parsing to user mode for better isolation and recoverability. The article explains that the faulty file system filter driver update triggered an out-of-bounds read leading to system crashes, and details Microsoft’s plans for safer rollouts, reduced kernel driver access to security data, enhanced isolation via VBS enclaves, and high-integrity attestation, while noting clarification on how the 8.5M impacted-device estimate was derived from a subset of crash reports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
