> Source: [sk181450](https://support.checkpoint.com/results/sk/sk181450)

# sk181450 - BSOD on Windows Server stations with Endpoint Security Firewall blade installed

| Property | Value |
|----------|-------|
| Solution ID | sk181450 |
| Date Created | 2023-09-05 |
| Last Modified | 2023-09-07 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- BSODs may occur during continuous extremely high network load per one socket with FW installed (e.g. server backup).

## Cause

The *vsdatant.sys* causes the issue.  

The *vsdatant.sys* (TrueVector Device driver) file is a Windows driver. It is a mandatory part of every Endpoint Security Client version running on Windows OS that implements client self-protection and network firewalling in case if Firewall Blade is installed.   

When Firewall blade is installed, the driver uses internal reference counter for every opened network socket to track its usage. Under certain conditions, this reference counter gets overflown causing the driver to use an incorrect memory block. When this happens, OS crashes with BSOD.   

Overflow of the counter occurs under intensive network throughput over the same network connection. The most common case is backing up a Server to a network target. For example, Veeam and Azure backups may trigger this. Because of specific conditions for the issue to exhibit itself it mainly happens on Windows servers and not on the workstations.

## Solution

This problem was fixed. The fix is included starting from:

* [Endpoint Security Client E87.50](https://support.checkpoint.com/results/sk/sk181265)

Check Point recommends to always upgrade to the [Recommended version.](https://support.checkpoint.com/results/sk/sk95746)

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue - improved Endpoint Security Client package.

A Support Engineer will make sure the Endpoint Security Client is compatible with your environment before providing it.  
For faster resolution and verification, collect the [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90445) file from the Endpoint Security Client involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
