2024 — On July 19, 2024, at 04:09 UTC, a Rapid Response…
Data compromised
Unknown
Technical writeup
On July 19, 2024, at 04:09 UTC, a Rapid Response Content update for the Falcon sensor was published to Windows hosts running sensor version 7.11 and above. This update was to gather telemetry on new threat techniques observed by CrowdStrike, but triggered crashes (BSOD) on systems that were online between 04:09 and 05:27 UTC. Mac and Linux hosts were not impacted. Windows hosts that were not online, or did not connect during this period, were not impacted. Why It Happened: Cause of Incident The crashes were due to a defect in the Rapid Response Content, which went undetected during validation checks. When the content was loaded by the Falcon sensor, this caused an out-of- bounds memory read, leading to Windows crashes (BSOD).
Root cause
Error/Misdelivery: Programming error
References
- https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update
- https://github.com/user-attachments/files/16515991/CrowdStrike-PIR-Executive-Summary.pdf
- https://github.com/user-attachments/files/16515993/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
- https://www.forbes.com/sites/kateoflahertyuk/2024/07/19/crowdstrike-windows-outage-what-happened-and-what-to-do-next/
- https://techcrunch.com/2024/07/24/crowdstrike-offers-a-10-apology-gift-card-to-say-sorry-for-outage/
- https://www.darkreading.com/cybersecurity-operations/crowdstrike-outage-losses-estimated-staggering-54b