Applications do not launch when Application and Device Control and CrowdStrike Falcon Sensor Platform are installed
search cancel

Applications do not launch when Application and Device Control and CrowdStrike Falcon Sensor Platform are installed

book

Article ID: 176409

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security Endpoint Security Complete

Issue/Introduction

When both CrowdStrike Falcon Sensor Platform and Symantec Endpoint Protection (SEP) Application and Device Control (ADC) are installed, some applications may fail or crash when launched.

 

Environment

Symantec Endpoint Protection Application and Device Control
CrowdStrike Falcon Sensor Platform

 

Cause

CrowdStrike Falcon Sensor (ScriptControl64_####.dll / umppc####.dll) injection appears to be using a hooking technique that does not conform with the method outlined by Microsoft Windows. 

 

Resolution

This issue is fixed in Symantec Endpoint Protection 14.3 RU4 and later. For information on how to obtain the latest build of Symantec Endpoint Protection, see Download Symantec Enterprise Security software.  

As a workaround Crowdstrike User Mode data can be disabled:

To disable "Additional User Mode Data" in CrowdStrike Falcon Sensor Platform.

  1. Log-in to the CrowdStrike Falcon Console.
  2. Click the Configuration app and then select Prevention Policies.
  3. Click the Edit icon on the desired policy group.
  4. Click Sensor Visibility.
  5. Turn off Additional User Mode Data.

If the above Crowdstrike steps cannot be taken or the client cannot be upgraded, adding SEP Application Control exclusions for the application(s) executable will allow the application to launch as expected.

 

Additional Information

ESCRT-2655 
SEP-75800