CrowdStrike (Falcon Sensor)
10736Warning Date
Severity Level
Warning Number
Target Sector
19 July, 2024
● High
2024-6292
All
CrowdStrike has announced a technical flaw in Falcon Sensor causing a denial of service on the affected systems.
Best Practices and Recommendations:
The CERT team encourages users to review CrowdStrike's security advisory and apply the necessary actions as follows:
- Boot Windows into Safe Mode or the Windows Recovery Environment.
- Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
- Delete the file C-00000291*.sys.
- Restart the system. (Shutdown /r)
- Boot the host normally.
Or perform the following command in Safe Mode:
del “ C:\Windows\System32\drivers\CrowdStrike\ C-00000291*.sys”
For more details apply CrowdStrike’s workaround as described in the following:
https://supportportal.crowdstrike.com/s/article/Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19