VMware confirms Carbon Black causing BSODs, boot loops on Windows
- Reference: 1661357290
- News link: https://www.theregister.co.uk/2022/08/24/vmware_carbon_black_boot_loop/
- Source link:
The issue – where PCs began booting into blue screens, some of which flashed the stop code PFN_LIST_CORRUPT – was apparently caused by a changed ruleset by the [1]company , which agreed to be acquired by Broadcom in May in a deal expected to close next year.
The problem surfaced yesterday, with threat hunter [2]Tim Geschwindt stating on Twitter he knew of about 50 organizations struggling with the issue, and saying the Carbon Black endpoint solution was "causing blue screens of death for devices running sensor version 3.7.0.1253" (later expanded to a broader range of sensors). The BSODs apparently began at 1430 UTC yesterday.
[3]
Over on Reddit, one admin [4]says the net effect was "servers and workstations bluescreening 'PFN_LIST_CORRUPT'," with another sysadmin saying they had been "told verbally by VMware that they are inundated."
[5]
[6]
VMware says in its [7]Knowledge Base article that the cause was some updated threat research rulesets rolled out to cloud regions in the US East, Asia Pacific, and the EU, which, it added, hadn't caused any trouble in its internal testing.
The problem affects devices running sensor versions from 3.6.x.x to 3.7.x.x, VMware says.
[8]
The virtualization giant, which hosts its VMware Explore event in San Francisco next week, has rolled back the rulesets, and promises that as machines check in, they will "get the updated ruleset and auto-resolve."
Admins have been told to place affected devices into [9]bypass mode via the Carbon Black Cloud Console to allow them to boot successfully and have the ruleset removed, although a "small subset" may require an additional workaround and those looking after them should open a support ticket. There's more information in the [10]Knowledge Base , and Carbon Black users should check for updates.
[11]VMware customers fear Broadcom acquisition will stall innovation, increase cost
[12]VMware reveals a swarm of serious bugs – some critical
[13]VMware president sees some 'anxiety' at customers who've seen Broadcom at work
[14]VMware fixes command injection, file upload flaws in Carbon Black security tool
[15]Aviation-themed phishing campaign pushed off-the-shelf RATs into inboxes for 5 years
Carbon Black, a suite of cloud-native endpoint protection tools aimed at bolstering enterprise cybersecurity, was acquired by VMware in 2019 to form the centerpiece of the company's new Security Business Unit.
The vendor [16]patched critical flaws in Carbon Black's App Control security tool earlier this year.
Tech analysts at Gartner have predicted that as VMware's new owner, Broadcom may rationalize some products after the acquisition closes, noting that [17]both Symantec and the Carbon Black unit offer endpoint protection products. The [18]deal is expected to close before the end of Broadcom's fiscal 2023, so by October next year.
[19]
We have asked VMware for comment. ®
Get our [20]Tech Resources
[1] https://www.theregister.com/2022/05/26/broadcom_buying_vmware_makes_sense/
[2] https://twitter.com/TGesches/status/1562119600816414721
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ywafd@d0nRpOJYWTVgSDvQAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.reddit.com/r/sysadmin/comments/wvs4sb/mass_bsod_on_windows_10_dell_laptops/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ywafd@d0nRpOJYWTVgSDvQAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ywafd@d0nRpOJYWTVgSDvQAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ywafd@d0nRpOJYWTVgSDvQAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-How-to-Enable-Disable-Bypass-from-the-Web/ta-p/74891
[10] https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369
[11] https://www.theregister.com/2022/06/09/gartner_broadcom_vmware_advice/
[12] https://www.theregister.com/2022/04/07/vmware_security_vmworld_explore/
[13] https://www.theregister.com/2022/07/19/vmware_president_sumit_dhawan_interview/
[14] https://www.theregister.com/2022/03/23/critical_bugs_vmware_carbon_black/
[15] https://www.theregister.com/2021/09/16/aviation_phishing_campaign_talos_five_years/
[16] https://www.theregister.com/2022/03/23/critical_bugs_vmware_carbon_black/
[17] https://www.theregister.com/2022/06/09/gartner_broadcom_vmware_advice/
[18] https://www.theregister.com/2022/07/06/broadcom_takeover_vmware/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ywafd@d0nRpOJYWTVgSDvQAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://whitepapers.theregister.com/
Re: Huh?
Carbon Black is a NGAV security product that VMWare acquired, it has nothing much to do with virtualization. For a period VMWare had competent leadership and was trying to diversify and become relevant so was investing in security and various cloud management things. Intel poached Gellsinger back and the VMWare board threw up their hands and took broadcoms' money because it was easier than being competitive. VMWare is a dying ship and these little things will happen since everybody is looking for a life-boat and not minding the boiler.
That didn't take long
I had commented earlier that merging VMware and Symantec would just degrade VMware to it's level(AKA 10 yards down the bog drain, next to McAffee, the company not the man, though it's possible him too if someone mistook his ashes for drugs, possibly due to their rock star level of residual drug content.)
Didn't think it would be this fast. Always great when software breaks in a way that needs to be fixed by contacting a cloud server that also prevents it from connecting to said cloud server. Luck there is was to disable in on boot. I'm sure that will be removed when they merge the code base with Symantec AV.
Uhhh.... Mr. El Reg
Broadcom has not completed the acquisition of VMWare (and CarbonBlack) at this time. They are still operating as independent companies, per SEC rules.
Huh?
I get that "Carbon Black" is some VMWare product relating to running virtual machines under Windows (or Windows running in a virtual machine, or both).
But what on earth does "sensor version" mean in relation to any of that?
(I figured I wouldn't be the only one who doesn't know, so I'm asking publically.)