CrowdStrike patch causing blue screen
Incident Report for UNC Chapel Hill - ITS
Resolved
This incident has been resolved.

The impact of this issue has declined thanks to the work of staff and customers. Refer to the ITS Service Desk for any remaining systems needing help.

Posted Jul 25, 2024 - 13:54 EDT
Update
University IT staff continue to assist customers in returning their computers to normal operations. If you are still experiencing any blue screen loops, please contact your local IT staff or the ITS Service Desk. For the latest information, read
CrowdStrike’s post
Posted Jul 19, 2024 - 16:22 EDT
Identified
TDX # 7545
Beginning at 1:21 am ITS began to receive reports of Windows systems that were not communicating with the network. Upon investigation it has been determined that some Windows servers and Windows endpoints (desktops/laptops) running the CrowdStrike Falcon Sensor and also having a particular file installed would blue screen and loop.

CrowdStrike has provided the following manual fix and it has proven to work. PLEASE NOTE: Windows systems and endpoints with BitLocker encryption may need BitLocker recovery keys to access safe mode. Departmental support will need to be engaged to access these keys. ITS can assist departmental IT as needed.

CrowdStrike Crashing Windows
Summary
CrowdStrike is aware of reports of crashes on Windows hosts related to the Falcon Sensor.
Details
Symptoms include hosts experiencing a bugcheck\blue screen error related to the Falcon Sensor.
Current Action
CrowdStrike Engineering has identified a content deployment related to this issue and reverted those changes.

If hosts are still crashing and unable to stay online to receive the Channel File Changes, the following steps can be used to workaround this issue:

Workaround Steps:
Boot Windows into Safe Mode or the Windows Recovery Environment
Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
Locate the file matching “C-00000291*.sys”, and delete it.
Boot the host normally
Posted Jul 19, 2024 - 05:01 EDT
Investigating
The ITS Operations Center has detected an issue impacting one or more of our services. Engineers have been engaged to investigate.
Posted Jul 19, 2024 - 03:16 EDT
This incident affected: Windows Services.