Home Microsoft issues report on what caused the huge Crowdstrike crash

Microsoft issues report on what caused the huge Crowdstrike crash

tl;dr

  • On July 19, CrowdStrike's faulty update caused global IT outages, mainly affecting flights and other industries.
  • Microsoft reported 8.5 million impacted Windows devices, with hospitals and businesses experiencing critical disruptions.
  • Both Microsoft and CrowdStrike are investigating the issue, with CrowdStrike's CEO apologizing for the malfunctioning update.

On July 19 the American cybersecurity company CrowdStrike put out a faulty update that shut down IT infrastructure and caused widespread outages across the world, mainly seen through the cancellation of flights but also felt in other industries.

It’s believed to be the largest technology outage in IT history; Microsoft has reported that around 8.5 million Microsoft Windows devices were impacted. Hospitals and other businesses were unable to carry out normal functions as the infamous “blue screen of death,” usually just an annoyance for personal computing users, brought an alarming number of critical services to a full stop.

Since the update failure, both Microsoft and Crowdstrike have been working to understand the issue and help those who have been affected. Microsoft published a technical analysis of the outage on Saturday (July 27), the same day that CrowdStrike published its Preliminary Post Incident Review on Saturday (27 July).

Microsoft confirms CrowdStrike outage reason following analysis

In CrowdStrike’s analysis, they say the issue came down to a memory safety issue which was a read out-of-bounds access violation in the CSagent driver. This is a module designed to detect activity that looks suspicious.

Microsoft has corroborated this and explains how its Kernel Debugger and other free-to-use extensions were used to find the memory safety issue to be the root cause.

The technology giant’s analysis included the team restoring the stack frame at the time of the access violation to learn more about its origin. However, due to only being able to see a compressed version, they were unable to disassemble backwards to see the larger set of instructions before the crash.

After explaining how they confirmed CrowdStrike’s analysis to be correct, they explained how the cybersecurity company loads four driver manuals in its kernel driver architecture.

They say this is commonplace due to the system-wide visibility it can present, along with potential performance benefits and the tamper resistance factor.

CrowdStrike has taken full responsibility for the outage and its chief executive has apologized for its malfunctioning software update.

Featured Image: Via Ideogram

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the tech industry for major developments, new product launches, AI breakthroughs, video game releases and other newsworthy events. Editors assign relevant stories to staff writers or freelance contributors with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Sophie Atkinson
Tech Journalist

Sophie Atkinson is a UK-based journalist and content writer, as well as a founder of a content agency which focuses on storytelling through social media marketing. She kicked off her career with a Print Futures Award which champions young talent working in print, paper and publishing. Heading straight into a regional newsroom, after graduating with a BA (Hons) degree in Journalism, Sophie started by working for Reach PLC. Now, with five years experience in journalism and many more in content marketing, Sophie works as a freelance writer and marketer. Her areas of specialty span a wide range, including technology, business,…

Get the biggest tech headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Tech News

    Explore the latest in tech with our Tech News. We cut through the noise for concise, relevant updates, keeping you informed about the rapidly evolving tech landscape with curated content that separates signal from noise.

    In-Depth Tech Stories

    Explore tech impact in In-Depth Stories. Narrative data journalism offers comprehensive analyses, revealing stories behind data. Understand industry trends for a deeper perspective on tech's intricate relationships with society.

    Expert Reviews

    Empower decisions with Expert Reviews, merging industry expertise and insightful analysis. Delve into tech intricacies, get the best deals, and stay ahead with our trustworthy guide to navigating the ever-changing tech market.