logo

How did a CrowdStrike config file crash millions of Windows computers? We take a closer look at the code

ID: cfd3444c-22a3-5b9c-a099-9eaa0ab4cff3

STIX ID: report--cfd3444c-22a3-5b9c-a099-9eaa0ab4cff3

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-07-23

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

On July 19, 2024 a CrowdStrike Falcon configuration update (a malformed channel file) caused the CSAgent.sys kernel component to perform an out-of-bounds memory read and repeatedly crash Windows hosts, reportedly impacting millions of machines (~8.5M) and causing widespread operational disruptions; analysis points to a bad pointer dereference in how the driver parsed the channel file rather than confirmed malicious tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.