This topic explains why the termdd blue screen error occurs on Windows Server 2008 R2 and how to resolve it.
Symptoms
A Windows Server 2008 R2 instance experiences a termdd blue screen error, which may include the bug check code 0x000000D1. The error screen displays the following information:
A problem has been detected and windows has been shut down to prevent damage
to your computer.
DRIVER_IRQL_NOT_LESS_OR_EQUAL
If this is the first time you've seen this Stop error screen,
restart your computer. If this screen appears again, follow
these steps:
Check to make sure any new hardware or software is properly installed.
If this is a new installation, ask your hardware or software manufacturer
for any windows updates you might need.
If problems continue, disable or remove any newly installed hardware
or software. Disable BIOS memory options such as caching or shadowing.
If you need to use Safe Mode to remove or disable components, restart
your computer, press F8 to select Advanced Startup Options, and then
select Safe Mode.
Technical information:
*** STOP: 0x000000D1 (0x0000000000000000,0x0000000000000002,0x0000000000000000,0xFFFFF88002B43006)
*** termdd.sys - Address FFFFF88002B430^In addition, a memory dump analysis shows that the version of the termdd.sys file, located at C:\Windows\System32\drivers\termdd.sys, is earlier than 6.1.7601.24441.
Cause
The cause is a system vulnerability that Microsoft patched on May 14, 2019. For more information, see CVE-2019-0708.
Resolution
Update the operating system.
Windows Update
Use Windows Update to install the latest system updates.
Connect to the ECS instance remotely.
For more information, see Connect to a Windows instance by using Workbench.
Modify the WSUS address in the registry.
Choose Start > Run, and then enter regedit.
Navigate to
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate. Set the values ofWUServerandWUStatusServertohttp://update.cloud.aliyuncs.com.
Choose Start > Control Panel > System and Security > Windows Update.
After the scan completes, click Install Updates.
After the updates are complete, restart the Windows instance.
Manual update
Connect to the ECS instance remotely.
For more information, see Connect to a Windows instance by using Workbench.
Download the cumulative security patch KB4499164 or the security-only update patch KB4499175.
Double-click the patch to install it.
Restart the Windows instance.
Common command
Log in to the ECS console.
In the left-side navigation pane, choose .
On the Common Commands tab, find the
ACS-ECS-ApplySecurityPatches-for-windows.ps1command and click Run.Select the Windows instance to update, configure the other parameters, and run the command.
For more information, see View and run common commands.
Verify that the issue is resolved.
Check the installed patches.
After you update the system, open Command Prompt and run the
systeminfocommand to view the installed patches. Verify that patch KB4499164 or KB4499175 is in the list.[55]: KB3156019 [56]: KB3159398 [57]: KB3161949 [58]: KB3161958 [59]: KB3172605 [60]: KB3177467 [61]: KB3179573 [62]: KB3181988 [63]: KB3210131 [64]: KB4019990 [65]: KB4040980 [66]: KB4093108 [67]: KB4103712 [68]: KB4284867 [69]: KB4338823 [70]: KB4343205 [71]: KB4343899 [72]: KB4457145 [73]: KB4462915 [74]: KB4467106 [75]: KB4471328 [76]: KB4474419 [77]: KB4480960 [78]: KB4486654 [79]: KB4489885 [80]: KB4493448 [81]: KB4499175 [82]: KB4503269 [83]: KB4507456Check the version of the
termdd.sysfile.Verify that the version of the
termdd.sysfile, located atC:\Windows\System32\drivers\termdd.sys, is 6.1.7601.24441 or later.
If the specified patch is installed and the version of the
termdd.sysfile is6.1.7601.24441or later, the blue screen error is resolved.