
The CrowdStrike outage was one of the most disruptive IT events in recent memory. What a way to start a Friday—a single faulty update to CrowdStrike’s Falcon sensor sent Windows machines into an endless blue-screen loop across airlines, banks, hospitals, and small businesses worldwide. If your team was hit, here’s exactly what happened and how to fix it.
What Caused the CrowdStrike Outage?
The CrowdStrike outage was triggered by a defective content update pushed to the Falcon endpoint-protection agent on Windows. The bad file caused the operating system to crash on boot, leaving affected computers stuck at the “blue screen of death.” Importantly, this was not a cyberattack—it was a flawed update. You can read CrowdStrike’s official statement here.
Because the problem lived in a driver that loads early in the boot process, machines couldn’t start Windows normally to receive a corrected update. That’s why the fix has to be applied by hand on each device.
How to Fix the CrowdStrike Outage
A fix is available to get systems back up and running. It does require physical (or remote console) access to each machine, because you need to boot into a recovery mode and remove the bad driver file. Follow these steps on each affected Windows host:
- Boot the affected Windows machine into Safe Mode or the Windows Recovery Environment.
- Navigate to the
C:\Windows\System32\drivers\CrowdStrikedirectory. - Find the file matching
C-00000291*.sysand delete it. - Reboot the host normally—it should come back up cleanly.
Good news: this update only affects Windows systems. Linux and macOS devices are not impacted, so you can focus your recovery effort where it’s needed.
Fixing the CrowdStrike Outage on Encrypted Machines
If your devices use BitLocker or another disk-encryption tool, you’ll need the recovery key before you can access the drivers folder in Safe Mode. Pull those keys from your management console first—hunting for them mid-crisis will slow everything down. This is one of the biggest bottlenecks businesses hit during the CrowdStrike outage.
How to Prevent the Next Outage Like This
Once the dust settles, it’s worth reviewing how updates reach your endpoints. Staggered or “canary” rollout rings, tested backups, and a documented recovery runbook all shorten the pain when a vendor ships a bad update. A little planning turns a company-wide emergency into a contained, few-hour inconvenience.
Why the CrowdStrike Outage Hit So Many Businesses
The reason the CrowdStrike outage spread so quickly comes down to how modern endpoint security works. Falcon runs at a very low level in Windows to catch threats early, so when its update was faulty, the operating system itself couldn’t start. Because the update rolled out automatically to every protected device at once, entire fleets went down within minutes—there was no gradual warning.
For small and mid-sized businesses, the impact was especially painful. Many don’t have a dedicated after-hours IT team, so a Friday-morning outage meant scrambling to touch every laptop and server by hand. If that sounds familiar, having a managed IT partner on call can turn a lost day into a quick, coordinated recovery. You can learn more about our managed IT and support services and how we help businesses stay resilient.
What to Do After the CrowdStrike Outage Is Resolved
Once your systems are back online, take a moment to document what happened while it’s fresh: which machines were affected, how long recovery took, and where you got stuck. That short write-up becomes the backbone of a recovery runbook you can lean on next time. Pair it with tested backups and a clear owner for update management, and you’ll be far better prepared for the next surprise—whether it’s a vendor bug or a genuine security incident.
Need Help Recovering From the CrowdStrike Outage?
If you’re staring down dozens (or hundreds) of blue-screened machines, you don’t have to work through them alone. Our team can help you triage the CrowdStrike outage, apply the fix at scale, and put safeguards in place so a single bad update never takes you down again.