Cybersecurity firm CrowdStrike has published its root cause analysis, detailing the Falcon Sensor software update bug that affected millions of Windows worldwide.
See also: CrowdStrike: Delta Air Lines refused free help

The root cause has been traced to a content validation issue that arose after the introduction of a new template type to enable visibility and detection of new attack techniques that abuse named pipes and other Windows IPC mechanisms.
Specifically, it relates to a problematic content update deployed via the cloud, with the company describing it as a “confluence” of multiple vulnerabilities that led to a crash – the most significant of which is a mismatch between the 21 inputs passed to the Content Validator via the IPC template type as opposed to the 20 provided to the Content Interpreter.
CrowdStrike said the parameter mismatch was not discovered during “multiple layers” of the testing process, in part due to the use of wildcard character matching criteria for the 21st input, during testing and in the initial IPC template instances delivered between March and April 2024.
See also: Shareholders sue CrowdStrike over global Blackout
In other words, the new version of Channel File 291, released on July 19, 2024, was the first instance of an IPC standard that made use of the 21st input parameter field. The lack of a specific test case for matching criteria without wildcards in the 21st field meant that this was not flagged until after the Rapid Response Content was sent to the sensors.

In addition to validating the number of input fields in the Template Type at sensor compile time to address the issue, CrowdStrike said it also added runtime input array bounds checks to the Content Interpreter to prevent out-of-bounds memory reads and corrected the number of inputs provided by the IPC template type.
Additionally, CrowdStrike said it plans to increase test coverage during Template Type development to include test cases for wildcard-free matching criteria for each field across all (future) template types.
Last but not least, CrowdStrike said it has hired two independent software security vendors to conduct further review of the Falcon sensor code for both security and quality assurance. It is also conducting an independent review of the end-to-end quality process.
See also: Delta Air Lines seeks damages from CrowdStrike and Microsoft
A few weeks ago, CrowdStrike experienced a major network outage that impacted services globally. The outage resulted in temporary unavailability for users who rely on its cybersecurity. During this outage, customers experienced delays in threat detection and response capabilities. The CrowdStrike team worked diligently to restore services, providing updates through its official channels. After the outage was resolved, an investigation was launched to assess the impact and prevent future incidents. Customers were advised to implement additional security measures during the outage and remain vigilant for any unusual activity.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
