Just last weekend, a large number of Windows users around the world encountered serious crashes due to a major bug in the security software CrowdStrike. This even included public institutions such as airports, hospitals, and banks, which had a considerable impact on the public. However, even though this incident was indeed very serious, the vast majority of users did not encounter any problems. According to recent data released by Microsoft, the number of Windows devices actually affected by this incident only accounted for 1% of the total.

The ratio of 1% may not seem high, but according to the global market share of Windows systems, this incident also affected up to 8.5 million related devices. Therefore, Microsoft promised to deploy hundreds of Windows engineers and experts to work with affected consumers to repair their devices. Microsoft is working directly with CrowdStrike to develop a solution, and the security company released an additional statement detailing the technical issues that caused the massive outage.
The origin of all these problems is a Config configuration file included in the latest update of CrowdStrike’s Falcon platform. The bug in this file caused a major logic error, which in turn caused Windows devices using the Falcon detection system to fall into a “Blue and White Screen of Death” (BSOD) crash loop.

The original purpose of this update was to “lock down newly observed malicious named pipes that are often used by C2 frameworks in network attacks.” However, after it was officially launched, this update not only failed to solve the problem, but also caused some very important infrastructure to fall into serious problems, triggering a huge chain reaction.
CrowdStrike subsequently fixed this logic error in subsequent updates, and Wesoft also released a client recovery tool to remove the problem. Before this tool was available, administrators needed to restart their Windows devices in safe mode or restore environment settings and manually remove files affected by the bug.

However, many users are curious about how an update with such a major bug could be released publicly like this in the first place, ultimately causing one of the worst crashes in history. Former Microsoft engineer David W Plummer published a post on Twitter comparing debuggers from his time on the Windows team and the differences between this incident.
How we did this in the old days:
When I was on Windows, this was the type of thing that greeted you every morning. Every. Single. Morning.You see, we all had a secondary "debug" PC, and each night we'd run NTStress on all of them, and all the lab machines. NTStress would… pic.twitter.com/rZkvpujbcr
— Dave W Plummer (@davepl1968) July 20, 2024
In this case, the problem lies in a CrowdStrike driver that passed the WHQL test. This program can download and execute p-code that is not registered by Microsoft, thus creating a security vulnerability. Basically, even though this third-party driver is indeed certified by Microsoft, it does bring some problematic updates on its own.

This incident caused serious crashes in the Windows systems of many important institutions around the world. While Microsoft has often been criticized for server-related issues in recent years, the mega-tech company has once again made headlines because of this incident, and it’s clear that this is not an honorable thing for Microsoft. For now, the problems caused by this incident seem to have at least been successfully resolved, but perhaps the Microsoft team will be more cautious when verifying updates to third-party software in the future.
Source: KOCPC Chinese