How did a CrowdStrike config file crash millions of Windows computers? We take a closer look at the code
ID: cfd3444c-22a3-5b9c-a099-9eaa0ab4cff3
STIX ID: report--cfd3444c-22a3-5b9c-a099-9eaa0ab4cff3
Feed Name: The Register (Security)
Threat Score
On July 19, 2024 a CrowdStrike Falcon configuration update (a malformed channel file) caused the CSAgent.sys kernel component to perform an out-of-bounds memory read and repeatedly crash Windows hosts, reportedly impacting millions of machines (~8.5M) and causing widespread operational disruptions; analysis points to a bad pointer dereference in how the driver parsed the channel file rather than confirmed malicious tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
