On July 19, 2024, CrowdStrike encountered a significant issue with their Falcon Sensor, which is essential for endpoint detection and response. A content update released that day caused Blue Screen of Death (BSOD) system crashes on Windows systems running Falcon Sensor version 7.11 and above. Additionally, a security vulnerability discovered by the Swiss security firm Modzero revealed that an attacker with administrative privileges could bypass the Falcon Sensor’s uninstall protection, allowing them to remove the sensor without the required token and compromising the security of the product. Modzero criticized CrowdStrike’s vulnerability disclosure process, leading to a public disclosure of the issue. The impacted file on Windows systems, a Channel File named "C-00000291-xxxx.sys" located in the directory C:\Windows\System32\drivers\CrowdStrike, is only 35 KB in size but caused significant disruption worldwide. Despite ending with a .sys extension, these Channel Files are not kernel drivers.