Sky-Knight
Well-Known Member
- Reaction score
- 5,788
- Location
- Arizona
Huge Microsoft Outage Caused by CrowdStrike Takes Down Computers Around the World
A software update from cybersecurity company CrowdStrike appears to have inadvertently disrupted IT systems globally.
I can't make up my mind between Crowdstrike or Sentinel One which of the two of them has crappier supply chain checks. It's like the Windows 98 patching days again all day every day with these two.
It's a oneliner to fix: del %WINDIR%\System32\drivers\CrowdStrike\C-00000291*.sys
The problem is, getting to the console to perform this deletion, and heaven help you if the drive is bitlockered. My NOC is mounting Azure hosted server disks to another VM do process the delete, and get the VMs there back online. VMWare / Hyper-V hosts once repaired are pretty quick, because physical console access to the platform gives you a repair command console pretty quickly.
But all the blasted endpoints that must be physically touched... it's an ugly weekend.
