Microsoft has published a technical analysis of the recent CrowdStrike incident, confirming that the root cause was a memory safety issue in the CSagent driver. The analysis used Windows Error Reporting kernel crash dumps to examine the crash and found a read-out-of-bounds access violation. The article also discusses the use of kernel-mode drivers by security products and the potential benefits of using user-mode alternatives. Microsoft highlights its own efforts to improve security and reliability in Windows.