PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Microsoft Reveals More Details About Windows CrowdStrike Crash

Microsoft acknowledges the inherent 'tradeoff' kernel-level cybersecurity solutions pose and confirms the root cause of the global outage.

 & Kate Irwin Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: Craig T Fruchtman/Contributor via Getty Images)

About a week after millions of Windows machines displayed the blue screen of death around the world, Microsoft has confirmed the root cause of the incident that grounded thousands of flights and disrupted numerous businesses and public services.

"Our observations confirm CrowdStrike’s analysis that this was a read-out-of-bounds memory safety error in the CrowdStrike developed CSagent.sys driver," Microsoft explains in its technical analysis of the crash published Saturday.

The report notes that CrowdStrike's driver was a file system filter driver, which are optional drivers that attach to the file software stack and are common for anti-malware agents. These drivers are different from device drivers like GPU drivers designed for a specific piece of hardware. CrowdStrike's service for Windows machines loads four driver modules, but one specific file is being blamed for the crash.

"We can see the control channel file version 291 specified in the CrowdStrike analysis is also present in the crash indicating the file was read," Microsoft notes, confirming CrowdStrike's previous assertion last week that an issue with that 291 channel file caused the IT meltdown.

Microsoft previously estimated that 8.5 million Windows computers were disabled by the CrowdStrike glitch. In its Saturday post, Microsoft shared that it received about 4 million crash reports on July 19 (not all users are opted-in to crash reports).

While Microsoft may be looking to further restrict access to its Windows kernel going forward, the tech giant also explained why it let third-parties access it in the first place. The Windows kernel is a deep layer of its operating system. Kernel-level cybersecurity lets developers do more to protect machines, can perform better, and can be harder for threat actors to alter or disable. When a kernel-level cybersecurity solution loads at the earliest possible time, it gives users the most data and context possible when threats arise.

In the world of competitive video games, for example, kernel-level anticheat systems are sometimes used to stop cheaters who run programs to add an aimbot or alter the physics of their games. But kernel-level anticheat solutions don't always work, and their wide-ranging permissions is a point of contention among some gamers.

Microsoft acknowledges that the tradeoff of kernel-level cybersecurity products is that if it glitches out, it can't be easily fixed. "All code operating at kernel level requires extensive validation because it cannot fail and restart like a normal user application," the company says.

"There is a tradeoff that security vendors must rationalize when it comes to kernel drivers," Microsoft shared. "Since kernel drivers run at the most trusted level of Windows, where containment and recovery capabilities are by nature constrained, security vendors must carefully balance needs like visibility and tamper resistance with the risk of operating within kernel mode."

About Our Expert

Kate Irwin

Kate Irwin

Reporter

I’m a reporter for PCMag covering tech news early in the morning. Prior to joining PCMag, I was a producer and reporter at Decrypt and launched its gaming vertical, GG. I have previously written for Input, Game Rant, Dot Esports, and other places, covering a range of gaming, tech, crypto, and entertainment news.

I’ve been a PC gamer since The Sims (yes, the original) in the CD-ROM days. I still think about my first-gen pink iPod mini, which, looking back, was not so mini. In 2020, I finally built my own custom Windows PC for gaming with a 3090 graphics card, but I also regularly use Mac and iOS devices. As a reporter, I’m passionate about documenting the wide world of tech and how it affects our daily lives.

My Areas of Expertise

  • Microsoft
  • Google
  • Artificial intelligence 
  • Cybersecurity
  • Video games are a big one. I specialize in shooters (Apex Legends, Fortnite, Overwatch) but I occasionally test out other genres as well, especially indie games or cozy games (The Sims series, Animal Crossing). 
  • The business and tech that powers video games
  • Cryptocurrency and blockchain technology
  • Social media platforms, including Meta’s apps, X/Twitter, Telegram, TikTok, etc.
  • Tech regulation

The Technology I Use

  • MSI gaming laptops
  • Nvidia graphics cards
  • AMD CPUs
  • MacBook Pro and Air laptops
  • An iPhone from 2019 (though I’m thinking about getting a “dumb phone” like the Light Phone)
  • Nintendo Switch
  • PlayStation 5
  • Freewrite Traveler 
  • At home: Sonos speakers (we have them all over the house), Philips Hue + Ring security products

Read full bio