* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, May 17, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Discover the World’s Richest Musician with a Fortune Close to $3 Billion – Can You Guess Who?

    Lincoln Adult Entertainment Store Hit by Burglars Twice in Less Than a Month

    From Raines to Reel Life: How This Creative Trailblazer is Transforming the Entertainment Industry

    Starz Entertainment Officer Granted 6,338 RSUs Vesting Through 2029

    Why Are Popular Netflix Shows Like ‘The Lincoln Lawyer’ and ‘Outer Banks’ Getting Cut Short?

    OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

    Disguise and Creative Technology Join Forces to Elevate Eurovision’s Stunning Visuals

    Revolutionizing Connectivity: Gi-Fi Technology Market Set to Soar by 2033

    Friday Harbor Becomes First Mortgage Tech Provider to Achieve AI Governance Compliance Certification

    Is Now the Ideal Time to Invest in People & Technology Inc.?

    How Minute Changes in RNA Powerfully Transform Our Innate Immune Defense

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Discover the World’s Richest Musician with a Fortune Close to $3 Billion – Can You Guess Who?

    Lincoln Adult Entertainment Store Hit by Burglars Twice in Less Than a Month

    From Raines to Reel Life: How This Creative Trailblazer is Transforming the Entertainment Industry

    Starz Entertainment Officer Granted 6,338 RSUs Vesting Through 2029

    Why Are Popular Netflix Shows Like ‘The Lincoln Lawyer’ and ‘Outer Banks’ Getting Cut Short?

    OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

    Disguise and Creative Technology Join Forces to Elevate Eurovision’s Stunning Visuals

    Revolutionizing Connectivity: Gi-Fi Technology Market Set to Soar by 2033

    Friday Harbor Becomes First Mortgage Tech Provider to Achieve AI Governance Compliance Certification

    Is Now the Ideal Time to Invest in People & Technology Inc.?

    How Minute Changes in RNA Powerfully Transform Our Innate Immune Defense

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Why did CrowdStrike cause the Windows Blue Screen?

July 23, 2024
in Technology
Why did CrowdStrike cause the Windows Blue Screen?
Share on FacebookShare on Twitter

Flavijus Piliponis â stock.ado

The ‘blue screen pf death’ signals a catastrophic Windows failure, which is exactly what many people faced on 19 July 2024 – but why did it happen?


Cliff Saran

By

Cliff Saran,
Managing Editor

Published: 23 Jul 2024 14:43

David William Plummer, a former Microsoft software engineer who developed Windows Task Manager, has posted a video describing how the CrowdStrike update could have caused Windows to halt. 

He described CrowdStrike Falcon as anti-malware for Windows servers, which “proactively detects new attacks” and analyses application behaviour. To do this, CrowdStrike needs to run as a kernel device driver.

Kernel device drivers usually provide a way to abstract hardware, such as graphics cards, from applications. When they run, they generally have full access to the computer and operating system and, in operating system terminology, they are said to run at “Ring Zero”. This is different to application code, which users run in the operating system’s user space known as “Ring One”.

The difference, as Plummer notes, is that when a user application crashes, nothing else on the computer should be affected. However, a fault in code running at Ring Zero is considered so serious that the operating system immediately halts, which, in Windows results in the so-called Blue Screen of Death.

“Even though there’s no hardware device that it’s really talking to, by writing the code as a device driver, CrowdStrike lives down in the kernel Ring Zero and has complete and unfettered access to the system data structures and the services that CrowdStrike believes it needs to do its job,” said Plummer.

Certified device drivers

Plummer noted that Microsoft, and likely also CrowdStrike, are aware of the stakes when software is running code in kernel mode, adding: “That’s why Microsoft offers the WHQL [Windows Hardware Quality Labs] certification.”

According to Plummer, the certification involves device driver software providers to test their code on various platforms and system configurations. The code is then signed digitally by Microsoft, which certifies that it is compatible with the Windows operating system. Plummer said the certifications process means that Windows users can be reasonably confident that the driver software is robust and trustworthy.

Certification is too slow to ensure anti-malware protection such as CrowdStrike is released as software updates every time there is a new threat. Plummer believes it is more likely that  CrowdStrike will often release a definition file that is processed by its Windows kernel driver. This gets around the WHQL device driver certification process and means users have access to the latest protection. 

“You can already perhaps see the problem,” he added. “Let’s speculate for a moment that the CrowdStrike dynamic definition file is not merely a malware definition but a complete program written in pseudocode that the driver can then execute.”

He said this would allow the device driver from CrowdStrike to execute the definition file as code running within the Windows kernel at Ring Zero even though the update itself has never been signed. “Executive p-code [pseudocode] in the kernel is risky at best and, at worst, is asking for trouble,” said Plummer.

By looking at crash dumps posted on X (formerly Twitter), Plummer said that a “null pointer reference” caused an empty file containing zeros to be uploaded by the CrowdStrike device driver, rather than the actual pseudocode.

“We don’t know how or why this happened, but what we know is that the CrowdStrike driver that handles and processes these updates is not very resilient and appears to have inadequate error-checking and parameter validation,” he added.

These are needed to ensure that data values required by the software are valid and good. If they are not, the error should not cause the entire system to crash, Plummer said. 

While it is often possible to restart Windows from the last known “good state”, which can remove rogue kernel drivers that prevent the operating system from booting up, Plummer said the situation was made worse by the fact that CrowdStrike is marked as a boot-start driver, which means it is needed for Windows to start up correctly.

While it is too early to understand how to ensure this never happens again, it is clear that there are serious limitations in Microsoft’s WHQL certification that allowed CrowdStrike to install an anti-malware update that had such a devastating impact across the Windows community.

Read more on Microsoft Windows software


Crowdstrike outage explained: What caused it and what’s next

SeanKerner

By: Sean Kerner


Defective CrowdStrike update triggers mass IT outage

RobWright

By: Rob Wright


CrowdStrike update chaos explained: What you need to know

AlexScroxton

By: Alex Scroxton


Okta: 4 customers compromised in social engineering attacks

ArielleWaldman

By: Arielle Waldman

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366596573/Why-did-CrowdStrike-cause-the-Windows-Blue-Screen

Tags: CrowdStriketechnologyWindows
Previous Post

By embracing liquid cooling, AI powerhouse Supermicro enables 30% more computing power — with the same power budget

Next Post

Hybrid multicloud storage: Pros, cons and key workloads

How Political Divides Are Driving Health Outcomes Across America

May 17, 2026

Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

May 17, 2026

Yankees Revamp Rotation After Cole’s Dominant Rehab Start

May 17, 2026

A Bold New Plan to Measure Our Nation’s Progress Toward the ’30 by 30′ Conservation Goal

May 17, 2026

Discover the Giant Blue Whale Skeleton Arriving Soon at Hatfield Marine Science Center in Newport

May 17, 2026

Argentina’s Science Funding Cuts Spark New Wave of Protests

May 17, 2026

Could a Strong, Sculpted Butt Be the Key to Men’s Longevity?

May 17, 2026

The World’s Largest Aircraft Carrier Returns from Historic 11-Month Deployment [Image 3 of 8] – DVIDS

May 17, 2026

The ‘K-Shaped’ Economy Is Transforming Into a Stark ‘E-Shaped’ Divide

May 17, 2026

Alumna Launches Bold Initiative to Solve Health Care Worker Shortage

May 17, 2026

Categories

Archives

May 2026
M T W T F S S
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,218)
  • Economy (1,240)
  • Entertainment (22,117)
  • General (21,560)
  • Health (10,273)
  • Lifestyle (1,252)
  • News (22,149)
  • People (1,241)
  • Politics (1,261)
  • Science (16,454)
  • Sports (21,738)
  • Technology (16,225)
  • World (1,231)

Recent News

How Political Divides Are Driving Health Outcomes Across America

May 17, 2026

Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

May 17, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version