THREAT LEVEL - HIGH

19-07-2024

CrowdStrike Outage Causes Huge Windows Blackout

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that a widespread Windows failure has brought down the computer systems of emergency services, banks, airports and more.

The widespread outage is linked to CrowdStrike, an American software technology company conducting an update to one of its platforms.

The affected systems are experiencing symptoms such as a “bugcheckblue screen error” and multiple system reboots.

The issue is creating havoc worldwide with reports of:

  • Flights being grounded at airports across the world
  • Online banking services refusing to let customers log in or transact
  • Broadcasters being forced off air

Please note that the a workaround has been released by the vendor, but due to the consequent reboots that the affected systems are experiencing, the vendor faces difficulties to remotely apply the relevant mitigations. Unfortunately in many cases it will have to be a manual intervention that has to be performed via a local admin account, and it will take a while at companies with huge fleets of Windows PC workstations to restore them.

Affected Systems

  • CrowdStrike Falcon Sensor

Recommendation(s)

You should not update to the latest version of CrowdStrike. If the update has already been installed and affected your systems, you should proceed immediately and roll back to the previous version.

A workaround offered by the vendor has been published:

  1. Booting Windows into Safe Mode or the Windows Recovery Environment
  2. Navigating to the C:WindowsSystem32driversCrowdStrike directory
  3. Locating the file matching “C-00000291*.sys” and deleting it, then
  4. Booting the host normally.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

https://www.forbes.com/sites/barrycollins/2024/07/19/huge-windows-blackout-hits-banks-airports-and-more/

https://thenightly.com.au/society/technology/crowdstrike-outage-what-we-know-so-far-about-the-global-it-blackout-c-15409253

https://www.helpnetsecurity.com/2024/07/19/crowdstrike-outage/

SIGN UP

Get the latest Threat Alerts in your inbox.