News » Explainers » Global Microsoft Meltdown: What Happened, Who Is Affected, What Is CrowdStrike Falcon, And How to Escape Blue Screen of Death?
5-MIN READ

Global Microsoft Meltdown: What Happened, Who Is Affected, What Is CrowdStrike Falcon, And How to Escape Blue Screen of Death?

Reported By:

Edited By: Pathikrit Sen Gupta

Last Updated:

New Delhi, India

Passengers wait at Barajas Airport after the Microsoft outage causing flight delays, in Madrid, Spain, July 19. Pic/Reuters

Passengers wait at Barajas Airport after the Microsoft outage causing flight delays, in Madrid, Spain, July 19. Pic/Reuters

The mass IT outage has caused chaos around the world, with major banks, media outlets, and airlines crippled. Many flights have been grounded, with queues and delays at airports, while shops and communications have also been hit

A major disruption in Microsoft’s cloud services has caused flight cancellations and delays across the globe, impacting key infrastructure. The company said impacted services may include, but are not limited to, services and software like PowerBI, Fabric, and Teams, as well as the Microsoft 365 admin center.

“We’re aware of an issue affecting Windows devices due to an update from a third-party software platform. We anticipate a resolution is forthcoming,” a Microsoft spokesperson told News18 without providing further details.

Airlines, Businesses Paralysed

The outage, which has affected numerous airlines, resulted in grounded planes and disrupted flight operations at Delhi and Mumbai airports in India. Among the airlines hit were IndiGo, Akasa, and SpiceJet.

The ripple effects were felt far and wide, with Virgin Australia, as well as Sydney and Melbourne airports, confirming operational disruptions. In the United States, major carriers including American Airlines, Delta Airlines, and United Airlines issued ground stops, citing communication issues just an hour after Microsoft resolved its cloud services outage that initially impacted several low-cost carriers.

The widespread outage has not been limited to the airline industry. Businesses around the world are experiencing outages, including the notorious Windows “blue screen of death” errors on their computers. This disruption is considered one of the most widespread in recent years, affecting various sectors from banks, hospitals and airlines. Many states across the US reported that their emergency 911 lines were down. In the UK, the London Stock Exchange and Sky News were among those affected. The Paris Olympics organising committee also said it had been hit by the outage, but that it had contingency plans in place.

Union Minister for Electronics and IT, Ashwini Vaishnaw stated: “MEITY is in touch with Microsoft and its associates regarding the global outage. The reason for this outage has been identified and updates have been released to resolve the issue.”

What Cert-In Advises

Cert-In, the Indian Computer Emergency Response Team under the Ministry of Electronics and Information Technology, in its latest advisory stated: “It has been reported that Windows hosts related to CrowdStrike agent Falcon Sensor are outages and getting crashed due to recent update received in the product. The concerned Windows hosts are experiencing a BSOD related to Falcon Sensor.”

It further added: “The issue occurred in the latest update of CrowdStrike and the changes have been reverted by the CrowdStrike team. If hosts are still crashing and unable to stay online to receive the Channel File Changes, the following steps can be used as work around for the issue… Also, users are advised to check the latest updates from the CrowdStrike portal.”

These steps include:

  • Boot Windows into Safe Mode or the Windows Recovery Environment.
  • Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
  • Locate and delete the file matching “C-00000291*.sys.”
  • Boot the host normally.

As the situation evolves, businesses and individuals are advised to stay updated through official Microsoft channels and take necessary precautions to mitigate the impact of this unprecedented outage.

CrowdStrike Update

Many customers have reported being unable to restart their computers due to this issue. The root cause of the disruption remains unclear, but some businesses, including Australian energy company AGL, have pointed to a recent update from the security firm CrowdStrike.

CrowdStrike is aware of the widespread reports of blue screen errors on Windows devices running multiple versions of its software and is actively investigating the cause. It is also said that a faulty update from CrowdStrike is believed to be responsible for the Blue Screen of Death (BSOD) issues, which have led to thousands of Windows machines being unable to boot properly. The update is causing affected PCs and servers to enter a recovery boot loop, preventing proper startup.

President and CEO of CrowdStrike George Kurtz said: “CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed. We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website. We further recommend organizations ensure they’re communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers.”

Falcon Sensor And Blue Screen Of Death

CrowdStrike is a US-based American cybersecurity firm that helps companies manage their security in “IT environments” — that is, everything they use an internet connection to access.

Its primary function is to protect companies and stop data breaches, ransomware, and cyber attacks.

One of the company’s main products is the CrowdStrike Falcon sensor, which is a key component of CrowdStrike’s endpoint protection platform. The software is installed on devices to provide real-time protection from cyber threats.

The main functions of the sensor include detecting threats, gathering data about devices, endpoint protection and sharing data with the CrowdStrike cloud for further processing.

CrowdStrike Falcon is used by thousands of companies across the world to protect data, and a crash of its server on Friday is believed to be the cause of a global outage of Microsoft products and BSOD issues.

The Blue Screen of Death is known as a blue screen, fatal error, or bug check, and is officially known as a stop error.

It is said to be a critical error screen displayed by the Microsoft Windows and ReactOS operating systems which indicates a system crash wherein the operating system reaches a critical condition where it may no longer operate safely.

First Alarm Bells In Australia, US

Some reports suggested that the initial alarms were raised by Australian banks, airlines, and TV broadcasters as thousands of machines began going offline. The problem has since spread to businesses in several parts of the world affecting critical infrastructure. However, it was also said that the chaos started with a cloud services outage in the US first, which was followed by massive IT problems in Australia that have now spread to Europe.

As of early Friday, multiple services and products across domains, including airlines, hotels, and office establishments, remained impacted globally due to the Blue Screen of Death error on most Microsoft Windows devices. Users have been unable to log into their systems as their devices crash after being switched on.

Microsoft has been actively updating its status and providing information via social media site X. Its statements include: “We’re investigating an issue impacting users ability to access various Microsoft 365 apps and services. More info posted in the admin center under MO821132 and on https://msft.it/6019lRURc.”

“Multiple services are continuing to see improvements in availability as our mitigation actions progress. More details can be found within the admin center under MO821132 and on https://status.cloud.microsoft,” the latest update states.

Microsoft ‘Service Health Status’ page lists a “Service Degradation” and details the impacted services, including PowerBI, Microsoft Fabric, Microsoft Teams, Microsoft 365 admin center, Microsoft Purview, and several others. They report that some services, such as Microsoft Defender and OneDrive for Business, are showing signs of recovery.

first published:July 19, 2024, 16:48 IST
last updated:July 20, 2024, 14:22 IST