CrowdStrike update triggers Windows blue screen crisis, Microsoft reveals the root cause

Publisher:心灵律动Latest update time:2024-07-29 Source: IT之家Keywords:Microsoft Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

July 29 news, over the past ten days, CrowdStrike and Microsoft have been working hard to assist users affected by the massive Windows blue screen of death problem. The problem was caused by a faulty update of CrowdStrike. In addition to providing a solution, CrowdStrike has released a preliminary post-incident review report on the outage. According to the report, the blue screen of death was caused by a memory safety issue, and an out-of-bounds read access violation occurred in CrowdStrike's CSagent driver.

Microsoft yesterday published a detailed technical analysis of the outage caused by the CrowdStrike driver. Microsoft's analysis confirmed CrowdStrike's findings that the crash was caused by an out-of-bounds memory safety error in CrowdStrike's CSagent.sys driver. The csagent.sys module registers as a file system filter driver on Windows computers to receive notifications about file operations, including the creation or modification of files, which allows security products, including CrowdStrike, to scan any new files saved to disk.

At the time of the incident, Microsoft was under heavy criticism for allowing third-party software developers to have kernel-level access. In a blog post, Microsoft explained why it provided kernel-level access to security products:

The kernel driver allows system-wide visibility and the ability to load early in the boot process to detect threats such as bootkits and rootkits, which can load before user-mode applications.

Microsoft provides functions such as system event callback and file filter driver.

The kernel driver provides better performance for situations such as high-throughput network activity.

Security solutions want to ensure that their software cannot be disabled by malware, targeted attacks, or malicious insiders, even if those attackers have administrator privileges. To this end, Windows provides Early Launch Antimalware (ELAM) early in the boot process.

However, kernel drivers also come with tradeoffs because they run at the most trusted level of Windows, increasing risk. Microsoft is also working on migrating complex Windows core services from kernel mode to user mode, such as font file parsing. Microsoft recommends that security solution providers balance the need for visibility and tamper resistance with the risks of kernel mode operations. For example, they can use minimal sensors that run in kernel mode for data collection and execution, thereby limiting exposure to usability issues. The remaining functions, such as managing updates, parsing content, and other operations, can be performed in isolation in user mode.

In the blog post, Microsoft also explained the built-in security features of the Windows operating system. These security features provide multiple layers of protection against malware and attack attempts. Microsoft will work with the anti-malware ecosystem through the Microsoft Virus Initiative (MVI) to further improve security and reliability using Windows built-in security features.

Microsoft currently plans to:

Provides secure deployment guidance, best practices, and technologies to make security product updates more secure.

Reduces the need for kernel drivers to access important security data.

Provides enhanced isolation and tamper resistance through technologies such as the recently announced VBS Islands.

Enable zero-trust approaches, such as high-integrity authentication, which determines the security posture of a machine based on the health of Windows native security features.

As of July 25, more than 97% of Windows computers affected by this issue are back online, and Microsoft is now looking to prevent such issues in the future. John Cable, Microsoft's vice president of Windows program management, recently published a blog post about the CrowdStrike issue, in which he mentioned that Windows must prioritize change and innovation for end-to-end resiliency, which is what customers expect from Microsoft.


Keywords:Microsoft Reference address:CrowdStrike update triggers Windows blue screen crisis, Microsoft reveals the root cause

Previous article:Edge AI meets the cloud: Making the right choice for your AI strategy
Next article:GigaDevice GD32H7 STL Software Test Library Obtains IEC 61508 Functional Safety Certification from TÜV Rheinland

Recommended ReadingLatest update time:2024-11-24 18:12

Microsoft files new patent for health tracking device
       Microsoft has canceled its Microsoft Band fitness bracelet project and ended support for fitness apps and services, but a new patent application suggests that Microsoft has not completely given up on the design.   IT Home learned that Microsoft obtained a new patent related to health tracking in June this yea
[Mobile phone portable]
Microsoft files new patent for health tracking device
ABB and Microsoft collaborate to bring generative AI to industrial applications
01 ABB and Microsoft collaborate to integrate generative capabilities into digital solutions for safer, more efficient and more sustainable operations 02 The collaboration aims to further unlock the value of contextual data through the deployment of Colot capabilities, making ABB’s Ability Gen
[robot]
Microsoft Surface Duo plastic frame may be broken
       IT Home reported on October 4 that according to MSPoweruser, Microsoft Surface Duo uses a plastic frame design, which can make the phone lighter, but it seems to have some disadvantages, such as easy breakage.   According to a report by Surface Duo user Algreimann on Reddit, the Surface Duo frame has begun to
[Mobile phone portable]
Introduction to Windows Platform Integrated Development Environment
At present, S698 series processors are widely used in electronics, communications, aerospace and other fields, but there is no Windows platform integrated development environment based on this architecture. Orion4.0 fills this gap. This article mainly introduces how to use the extensible Java development platform pl
[Industrial Control]
Introduction to Windows Platform Integrated Development Environment
Nvidia drivers don't play well with older processors, causing blue screens of death on Windows PCs
On August 5, some users reported that their computers with old processors experienced a blue screen crash after installing the latest version of NVIDIA graphics card drivers. After verification, it was found that the problem was caused by NVIDIA's termination of driver support for processors that do not support the
[Embedded]
Nvidia drivers don't play well with older processors, causing blue screens of death on Windows PCs
Nokia Lumia imaging expert joins Microsoft Surface team, expected to significantly improve photography
     Foreign media Windows Latest reported that now, Ari Partinen, head of Microsoft's Nokia Lumia imaging experts, has joined Microsoft's Surface department to develop new imaging solutions for Surface products such as Surface Pro and Surface Duo.   Ari Partinen previously worked as an "image quality" expert at Nok
[Mobile phone portable]
Nokia Lumia imaging expert joins Microsoft Surface team, expected to significantly improve photography
Latest Embedded Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号