• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Global Microsoft outage hits due to CrowdStrike Update Definitions

erek

[H]F Junkie
2FA Enabled
Joined
Dec 19, 2005
Messages
12,824
… and hits hard too!


Source: https://www.cnn.com/business/live-news/global-outage-intl-hnk/index.html
 
Given that this seems to stem from security software, I'll venture to guess that the cause will turn out to be a problem in kernel-privileged drivers installed by said software.
 
Given that this seems to stem from security software, I'll venture to guess that the cause will turn out to be a problem in kernel-privileged drivers installed by said software.
Yes it's a Crowdstrike kernel driver. They decided to not test it (given how much it's failing, it feels that way) and release it on a Friday/Thursday (timezones..). Masterstroke.
 
Last edited:
Screenshot_20240719-092237.png
 
My management drinks full Microsoft Kool-Aid, but we don't use Crowdstrike. My fear is that after the big M365/Azure outage, they'll say, "Wait a minute, Microsoft uses Crowdstrike and we don't? Gotta fix that next year."
 
The bad update has been pulled by Crowdstrike.

Apparently the fix is to boot the machines in safe mode and remove a sys file from the crowdstrike folder.

I imagine some poor windows admin right now like "I have to safe mode boot...500 systems?"
 
The bad update has been pulled by Crowdstrike.

Apparently the fix is to boot the machines in safe mode and remove a sys file from the crowdstrike folder.

I imagine some poor windows admin right now like "I have to safe mode boot...500 systems?"

I am sure there are orgs out there with way more then 500.

AWS EC2 admins have it worse in my opinion...one of my criticisms about EC2 is them not giving "console" access to the EC2 VM's and you can only RDP. Its a nightmare for the whole "clone your EBS volume, mount it to another machine that works, clear the file, unmount, etc" procedure.
 
The fix just so it's in plain-text here:

1) boot to safe mode, login as ADM
2) C:\Windows\System32\drivers\CrowdStrike\C-00000291* Delete this file.
3) Reboot

Personally, I'm making the rounds on about 200 of our VM's.... pouring one out tonight whenever I get off work for sure!
 
The bad update has been pulled by Crowdstrike.

Apparently the fix is to boot the machines in safe mode and remove a sys file from the crowdstrike folder.

I imagine some poor windows admin right now like "I have to safe mode boot...500 systems?"

Got called this morning around 7 to hop on a conference bridge to do just that .. fun times..

Apparently there is some sort of script/workaround.. involving putting a group policy in place to set safemode via bcdedit.. and remove the file..
then reverse the bcdedit settings..
 
The fix just so it's in plain-text here:

1) boot to safe mode, login as ADM
2) C:\Windows\System32\drivers\CrowdStrike\C-00000291* Delete this file.
3) Reboot

Personally, I'm making the rounds on about 200 of our VM's.... pouring one out tonight whenever I get off work for sure!
The official fix statement,

"To Fix CrowdStrike Blue Screen of Death Simply Reboot 15 Straight Times, Microsoft Says"
 
The official fix statement,

"To Fix CrowdStrike Blue Screen of Death Simply Reboot 15 Straight Times, Microsoft Says"

That is for Azure VM's...
YES... we are dealing with this fiasco also.... no console access to a Windows VM in the cloud.... ugh... fun times
 

that part of the forum is only for paid subscribers...don't worry about it...that pendragon guy is obsessed with telling people to post in other threads...he's not a Mod or Admin...it's perfectly fine to post in the News section...I don't think he understands what a News section is...everything could theoretically be posted in another section but that's why it's called 'News'
 
that part of the forum is only for paid subscribers...don't worry about it...that pendragon guy is obsessed with telling people to post in other threads...he's not a Mod or Admin...it's perfectly fine to post in the News section...I don't think he understands what a News section is...everything could theoretically be posted in another section but that's why it's called 'News'
thats not even whats going on here but reeeeeee some more.
 
that part of the forum is only for paid subscribers...don't worry about it...that pendragon guy is obsessed with telling people to post in other threads...he's not a Mod or Admin...it's perfectly fine to post in the News section...I don't think he understands what a News section is...everything could theoretically be posted in another section but that's why it's called 'News'
he might soon be a mod or admin, so worry about it

.. i think
 
I'm in Cozumel and a couple hours away from flying back to San Antonio. So far my Southwest flight isn't delayed.
 
I naively vastly underestimated how much windows system there still was when you are not forced in any way to use it (maybe where the naivety come from), one would have thought in 2024 that big airlines chain terminal, hostel and so on where not Windows anymore..., maybe I underestimate how good Windows is for that kind of stuff...
 
Production alert went out for my company, one of the largest banks in the US. Unfortunately it's having zero direct impact to my operations, but I assume it's going to be a slower day because my customers are impacted outside of my product/application and wont be bothering me today.
 
Back
Top