TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor
CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor.
Vulnerable Version And Products
- Latest version of CrowdStrike Falcon Agent on Windows
Fixes and workaround
- Boot Windows into Safe Mode or the Windows Recovery Environment
- Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
- Locate the file matching
C-00000291*.sys, and delete it. - Boot the host normally.
We received reports that only the Windows Recovery Environment mode works, as the driver still seems to be loaded in safe mode.