************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
EnableRedirectToChakraJsProvider : false
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.031 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 45
Microsoft (R) Windows Debugger Version 10.0.27871.1001 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\User\AppData\Local\Temp\Rar$DIa2748.6693.rartemp\090125-15906-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Kernel base = 0xfffff804`25e00000 PsLoadedModuleList = 0xfffff804`26a2a3f0
Debug session time: Mon Sep 1 04:05:32.219 2025 (UTC + 3:00)
System Uptime: 0 days 1:42:30.869
Loading Kernel Symbols
..
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.............................................................
................................................................
................................................................
..............
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000ff`03e5c018). Type ".hh dbgerr001" for details
Loading unloaded module list
.......
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff804`261fd510 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffa300`845aece0=0000000000000139
8: kd> !analyze -v
Loading Kernel Symbols
..
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.............................................................
................................................................
................................................................
..............
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000ff`03e5c018). Type ".hh dbgerr001" for details
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 000000000000001d, An RTL_BALANCED_NODE RBTree entry has been corrupted.
Arg2: ffffa300845af000, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffa300845aef58, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1546
Key : Analysis.Elapsed.mSec
Value: 4439
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 2
Key : Analysis.Init.CPU.mSec
Value: 3062
Key : Analysis.Init.Elapsed.mSec
Value: 26347
Key : Analysis.Memory.CommitPeak.Mb
Value: 108
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : Dump.Attributes.AsUlong
Value: 0x8
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : FailFast.Name
Value: INVALID_BALANCED_TREE
Key : FailFast.Type
Value: 29
Key : Failure.Bucket
Value: 0x139_1d_INVALID_BALANCED_TREE_nt!KiFastFailDispatch
Key : Failure.Exception.Code
Value: 0xc0000409
Key : Failure.Exception.Record
Value: 0xffffa300845aef58
Key : Failure.Hash
Value: {67ec97ad-ad0b-071e-ab87-6dc661e22d1b}
BUGCHECK_CODE: 139
BUGCHECK_P1: 1d
BUGCHECK_P2: ffffa300845af000
BUGCHECK_P3: ffffa300845aef58
BUGCHECK_P4: 0
FILE_IN_CAB: 090125-15906-01.dmp
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
FAULTING_THREAD: ffff8c88568ef080
TRAP_FRAME: ffffa300845af000 -- (.trap 0xffffa300845af000)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=000000000000001d
rdx=ffffd50be8a01ee0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80426254789 rsp=ffffa300845af190 rbp=0000000000000000
r8=ffffd50bea501bc0 r9=ffffd50bea701100 r10=ffffd50bd3c00160
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe cy
nt!RtlRbInsertNodeEx+0x193c79:
fffff804`26254789 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffffa300845aef58 -- (.exr 0xffffa300845aef58)
ExceptionAddress: fffff80426254789 (nt!RtlRbInsertNodeEx+0x0000000000193c79)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 000000000000001d
Subcode: 0x1d FAST_FAIL_INVALID_BALANCED_TREE
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: sppsvc.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 000000000000001d
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffffa300`845aecd8 fffff804`26211da9 : 00000000`00000139 00000000`0000001d ffffa300`845af000 ffffa300`845aef58 : nt!KeBugCheckEx
ffffa300`845aece0 fffff804`26212350 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffa300`845aee20 fffff804`262101f2 : 00000000`00000000 00000000`00000001 ffffa300`845af160 ffff8c88`568ef080 : nt!KiFastFailDispatch+0xd0
ffffa300`845af000 fffff804`26254789 : 00000000`00000000 fffff804`2608b0ab ffffd50b`d3c00100 ffffd50b`d3c00100 : nt!KiRaiseSecurityCheckFailure+0x332
ffffa300`845af190 fffff804`2608b0ab : ffffd50b`d3c00100 ffffd50b`d3c00100 00000000`00000001 ffffd50b`d7101ce0 : nt!RtlRbInsertNodeEx+0x193c79
ffffa300`845af1a0 fffff804`260aa125 : ffffd50b`d7101ce0 ffffa300`845af438 ffffd50b`d7101ce0 00000000`00000004 : nt!RtlpHpSegFreeRangeInsert+0xcb
ffffa300`845af1d0 fffff804`260c2951 : ffffd50b`dbb53010 ffffa300`845af47c ffffa300`d71000ff 6ff55d19`00000000 : nt!RtlpHpSegPageRangeShrink+0xa5
ffffa300`845af240 fffff804`260c281d : ffffd50b`d3c00000 0000000e`5254f38f ffffd50b`dbeb2010 00000000`00000000 : nt!RtlpHpSegFree+0xc1
ffffa300`845af280 fffff804`260c2389 : ffffd50b`db8e6bc0 ffffd50b`d3c00000 ffffd50b`d71e7000 ffffd50b`d71e7000 : nt!RtlpHpFreeHeap+0x8d
ffffa300`845af2d0 fffff804`267b4149 : 00000000`00000000 00000000`00000001 01000000`00100000 00000000`00000000 : nt!ExFreeHeapPool+0x239
ffffa300`845af390 fffff804`2646b84b : ffffd50b`dbeb2010 ffff8c88`5246e2f0 ffff8c88`5246e2f0 00000000`00001000 : nt!ExFreePool+0x9
ffffa300`845af3c0 fffff804`2646a78c : ffffffff`ffffffff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiValidateSectionCreate+0x63f
ffffa300`845af5a0 fffff804`2646a6b2 : ffffa300`845af840 00000000`00000002 00000000`00000001 00000000`00000000 : nt!MiValidateSectionSigningPolicy+0xac
ffffa300`845af600 fffff804`26455543 : 00000000`00000002 ffffa300`00000000 ffff8c88`5b264cf0 ffffa300`845af840 : nt!MiValidateExistingImage+0x2ba
ffffa300`845af6a0 fffff804`2645474d : 00000000`00000000 ffffa300`845af840 ffff8c88`568ef080 ffff8c88`5b264cf0 : nt!MiShareExistingControlArea+0xc7
ffffa300`845af6d0 fffff804`26452e94 : ffff8c88`5246e2f0 00000000`00000000 ffff8c88`5b264cf0 00000000`00000000 : nt!MiCreateImageOrDataSection+0x1ad
ffffa300`845af7c0 fffff804`26454cc7 : 00000000`01000000 ffffa300`845afb80 00000000`00000001 00000000`00000010 : nt!MiCreateSection+0xf4
ffffa300`845af940 fffff804`26454eac : 000000ff`040ff828 00000000`0000000d 00000000`00000000 00000000`00000001 : nt!MiCreateSectionCommon+0x207
ffffa300`845afa20 fffff804`26211508 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateSection+0x5c
ffffa300`845afa90 00007ff9`9dd2de34 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000ff`040ff7d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`9dd2de34
SYMBOL_NAME: nt!KiFastFailDispatch+d0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.6216
STACK_COMMAND: .process /r /p 0xffff8c8855316080; .thread 0xffff8c88568ef080 ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: 0x139_1d_INVALID_BALANCED_TREE_nt!KiFastFailDispatch
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {67ec97ad-ad0b-071e-ab87-6dc661e22d1b}
Followup: MachineOwner
---------
8: kd> lmvm nt
Browse full module list
start end module name
fffff804`25e00000 fffff804`26e46000 nt (pdb symbols) C:\ProgramData\Dbg\sym\ntkrnlmp.pdb\B6121DA15DDCF625C8C7273C0D85EB101\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\BCA5A8DD1046000\ntkrnlmp.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data Symbol Reload
Image was built with /Brepro flag.
Timestamp: BCA5A8DD (This is a reproducible build file hash, not a timestamp)
CheckSum: 00A6AFFA
ImageSize: 01046000
File version: 10.0.19041.6216
Product version: 10.0.19041.6216
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.19041.6216
FileVersion: 10.0.19041.6216 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.