Carbon Black Cloud: BSOD caused by ntkrnlmp.exe
search cancel

Carbon Black Cloud: BSOD caused by ntkrnlmp.exe

book

Article ID: 287473

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

System crashed when running CBC sensor, and got the following related module in dump file:

SYMBOL_NAME:  nt!MmDeleteProcessAddressSpace+xxxxxx
MODULE_NAME: nt
IMAGE_VERSION:  10.0.xxxxx.xxx
STACK_COMMAND:  .thread ; .cxr ; kb
IMAGE_NAME:  memory_corruption

 

Environment

  • Carbon Black Cloud: All Supported versions
  • Microsoft Windows: All supported versions

Cause

All bugchecks are caused by an incorrect driver. Outdated and incompatible device drivers are known to work against the methods that Windows 10 follows.

Resolution

  1. Obtain the latest version of  the impacted driver from the device manufacturer.
  2. Check if other device drivers are updated to the latest version.
  3. Download and install the latest version of all drivers.