Crowdstrike Issue Causes Windows Blue Screen Error
Incident Report for MIT
Resolved
This incident has been resolved.
Posted Jul 29, 2024 - 10:51 EDT
Monitoring
A fix has been implemented and we are monitoring the results.
Posted Jul 22, 2024 - 09:35 EDT
Identified
A recent worldwide Crowdstrike update is causing a Windows OS blue screen error on all versions of the Windows operating system running the Crowdstrike software.

Crowdstrike has released an update to resolve the issue. To apply the update to an impacted machine, restart it.

If you continue to experience difficulty following a restart, the following steps are a workaround solution:

1. Boot Windows into Safe Mode or the Windows Recovery Environment
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
3. Locate the file matching “C-00000291*.sys”, and delete it.
4. Boot the host normally.

The steps above require administrative access to complete.

IS&T is working to restore central services that rely on Microsoft Windows.

Crowdstrike has posted a statement on the incident: https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/

If you require assistance with the workaround, obtaining admin credentials, or a Bitlocker recovery key, please contact the Service Desk at 617-253-1101 or servicedesk@mit.edu.
Posted Jul 19, 2024 - 03:39 EDT
This incident affected: General.