What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A faulty CrowdStrike Falcon security-content update—not a Microsoft-distributed Windows update or a cyberattack—caused some Windows systems to crash on July 19, 2024. CrowdStrike says the affected content was released at 04:09 UTC and reverted at 05:27 UTC. Microsoft estimated on July 20 that 8.5 million Windows devices were affected, less than one percent of all Windows machines.

What happened on July 19, 2024?

CrowdStrike’s Falcon security software receives Rapid Response Content through Channel Files, separately from fixed Sensor Content included in a sensor release. On July 19, a Rapid Response Content update in Channel File 291 caused some Windows computers running sensor version 7.11 or later to crash after receiving the content during the 04:09–05:27 UTC window. CrowdStrike says it reverted the defective content at 05:27 UTC; its preliminary review said Mac and Linux hosts were not affected. CrowdStrike’s preliminary incident review describes the affected window and scope.

Microsoft explicitly described the event as not a Microsoft incident. It was a failure involving CrowdStrike’s security software content and sensor, rather than a Windows update distributed by Microsoft. Microsoft’s July 20 response provides its estimate of the impact.

How many devices were affected?

On July 20, 2024, David Weston, Microsoft’s Vice President of Enterprise and OS Security, said: “We currently estimate that CrowdStrike’s update affected 8.5 million Windows devices, or less than one percent of all Windows machines.” This was Microsoft’s estimate during the response, not a live count or a claim that all Windows devices were affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
5-in-1 Win Repair & Reinstall Bootable USB Flash Drive – Fix, Recover, or Reinstall Windows 11 (amd64 + arm64) / 10/7 - Includes PE Tools, Driver Pack, Antivirus, Data Recovery & Password Reset
  • Dual USB-A & USB-C Bootable Drive – compatible with nearly all Windows PCs, laptops, and tablets (UEFI & Legacy BIOS). Works with Surface devices and all major brands.
  • Fully Customizable USB – easily Add, Replace, or Upgrade any compatible bootable ISO app, installer, or utility (clear step-by-step instructions included).
  • Complete Windows Repair Toolkit – includes tools to remove viruses, reset passwords, recover lost files, and fix boot errors like BOOTMGR or NTLDR missing.
  • Reinstall or Upgrade Windows – perform a clean reinstall of Windows 7 (32bit and 64bit), 10, or 11 (amd64 + arm64) to restore performance and stability. (Windows license not included.). Includes Full Driver Pack – ensures hardware compatibility after installation. Automatically detects and installs drivers for most PCs.
  • Premium Hardware & Reliable Support – built with high-quality flash chips for speed and longevity. TECH STORE ON provides responsive customer support within 24 hours.

Why did the update crash Windows systems?

CrowdStrike’s August 6, 2024 root-cause analysis says the failure involved a mismatch between a template’s declared input count and the number of values supplied to it, compounded by missing runtime checks and gaps in validation and testing. The faulting component was CrowdStrike’s csagent.sys file-system filter driver; CrowdStrike characterizes the failure as a memory read fault. The explanation below reflects the company’s published account, not an independent forensic finding.

The template expected 21 inputs but received 20

The affected IPC Template Type declared 21 input fields, while the integration code supplied 20. Earlier test templates used wildcard matching for the 21st field, so the mismatch did not expose the problem in those tests. The July 19 template used a non-wildcard condition for that field.

A Windows notification triggered the faulty read

When the sensor received a relevant Windows named-pipe notification, its Content Interpreter evaluated the new template. It attempted to read a 21st value from an array containing only 20 values. CrowdStrike says that out-of-bounds read caused the sensor driver to fault and the Windows system to crash.

CrowdStrike’s Channel File 291 root-cause analysis and remediation guidance identifies the field-count mismatch, absent runtime check, validator assumptions, and test gap as parts of the failure chain. It also lists additional input validation and bounds checks, broader test coverage, staged rollout, and customer control over Rapid Response Content delivery among the measures to address the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How could affected Windows devices be recovered?

Microsoft’s administrator guidance, KB5042429, documents recovery options using Windows Preinstallation Environment (Windows PE), Safe Mode, or—in environments configured for it—PXE boot. The appropriate option depends on the device, access to recovery media and the network, local administrator access, and BitLocker configuration. These are administrator-oriented procedures; if the PC belongs to an organization, users should follow its IT support process rather than attempting an unfamiliar workaround.

Rank #2
SANDISK 128GB Ultra Flair, USB-A Flash Drive, Up to 150MB/s Read Speeds
  • High-speed USB 3.0 performance of up to 150MB/s(1) [(1) Write to drive up to 15x faster than standard USB 2.0 drives (4MB/s); varies by drive capacity. Up to 150MB/s read speed. USB 3.0 port required. Based on internal testing; performance may be lower depending on host device, usage conditions, and other factors; 1MB=1,000,000 bytes]
  • Transfer a full-length movie in less than 30 seconds(2) [(2) Based on 1.2GB MPEG-4 video transfer with USB 3.0 host device. Results may vary based on host device, file attributes and other factors]
  • Transfer to drive up to 15 times faster than standard USB 2.0 drives(1)
  • Sleek, durable metal casing
  • Easy-to-use password protection for your private files(3) [(3)Password protection uses 128-bit AES encryption and is supported by Windows 7, Windows 8, Windows 10, and Mac OS X v10.9 plus; Software download required for Mac, visit the SanDisk SecureAccess support page]
Recovery route When it may fit Access or preparation to check
Windows PE with Microsoft’s recovery tool When an administrator can boot the device from recovery media; the tool can automate remediation. A BitLocker recovery key may be needed. USB media creation requires a 64-bit Windows client with at least 8 GB free and a USB drive from 1 GB through 32 GB. Creating the media formats the drive and deletes its existing contents.
Safe Mode and administrator steps When recovery can be performed from the affected Windows installation. A local administrator account is required. TPM+PIN configurations may still require the PIN or BitLocker recovery key.
PXE boot When USB recovery is unavailable and the device can reach an existing PXE environment. Requires an available, configured PXE environment and administrator access to use it.
Manual recovery or reimaging When the documented boot-media options are unavailable or do not resolve the problem. Microsoft provides manual instructions and notes that reimaging might be a solution; the right choice depends on the device and organization’s recovery process.

For IT teams preparing recovery media

Microsoft’s documented USB creation process erases the selected drive. Confirm that it contains no needed files before using it. Microsoft advises testing the recovery process on multiple devices before broad deployment, since device configurations and recovery prerequisites can differ.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did the incident reveal about software deployment?

The failure was not attributable to one mismatch alone: CrowdStrike’s account describes a chain involving the declared-versus-supplied field count, the missing runtime check, validator assumptions, and a test gap. Its listed corrective measures—stronger validation and bounds checks, broader testing, staged rollout, and customer control over content delivery—address different points in that chain.

Microsoft emphasized the interdependence of cloud providers, software platforms, security vendors, and customers, and called attention to safe deployment and disaster recovery across the technology ecosystem. In its July 29, 2024 root-cause analysis, CrowdStrike reported that about 99% of Windows sensors were online compared with before the content update. The company also noted that sensor connections typically vary by about 1% week over week, so that comparison is not a count of individually repaired computers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can organizations avoid recovery-related scams?

The Center for Internet Security reported phishing campaigns and spoofed domains targeting organizations responding to the outage. Treat unsolicited recovery links, downloads, and instructions with caution. Organizations should use official Microsoft and CrowdStrike support channels and their own IT procedures rather than unverified workarounds. CIS’s CrowdStrike outage resources provides response guidance spanning endpoint and cloud environments.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.