Microsoft Outlook Application Crash due to UCRTBASE.DLL

Anonymous
2020-12-07T17:43:25+00:00

Windows 10 Build 2004

Outlook crashes intermittently and generates the following Application Event Log error.

Event 1000, Application Error (11:06AM, 12/7/2020) Faulting application name: OUTLOOK.EXE, version: 16.0.13426.20308, time stamp: 0x5fc6ea9b Faulting module name: ucrtbase.dll, version: 10.0.19041.546, time stamp: 0x73123758 Exception code: 0xc0000409 Fault offset: 0x0009edbb Faulting process id: 0x41c0 Faulting application start time: 0x01d6ccaedccaa9fa Faulting application path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: f8791f7b-faf7-452a-8ff2-7268662a6db2 Faulting package full name: Faulting package-relative application ID:

I have run SFC /SCANNOW

I have completely uninstalled and reinstalled Microsoft Office 365

Here are the properties of the failing file:

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

69 answers

Sort by: Most helpful
  1. Anonymous
    2021-02-04T11:53:12+00:00

    Afraid not, it may be similar issue with another security platform.  Check your AV, perhaps disable for a period to test.  For the majority on this threat, Sophos Exploit Mitigation was the cause, but we dont have a common 3rd party app that links it all.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-02-04T11:23:39+00:00

    Hello GD.

    I do not have the software Sophos,Do you know another solution to the problem of crashes?

    Thank you

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-02-04T10:44:47+00:00

    Latest from Sophos, has moved to Dev team.  Should be fixed globally now without needing the exploit mitigation disabled.

    We've identified an issue with a new DCOMLockdown mitigation technique that is part of Intercept X protections, which wecurrently test, that could cause Outlook to crash, logging the following entryin the application Eventlog:

    Error    19.01.2021 17:29:39    ApplicationError    1000    (100)
    Faulting application name: OUTLOOK.EXE, version: 16.0.13530.20376, time stamp:0x5ffa7614
    Faulting module name: ucrtbase.dll, version: 10.0.19041.546, time stamp:0x43cbc11d
    Exception code: 0xc0000409
    Fault offset: 0x000000000007287e
    Faulting process id: 0x6d24
    Faulting application path: C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
    Faulting module path: C:\WINDOWS\System32\ucrtbase.dll

    Due to the low number of Support Cases we received on the reported issue, wesuspect the crashes to be influenced by another third party application (likean Outlook Add-in), which is currently under investigation by our DevelopmentTeams.

    We are going to mitigate the reported issue by disabling the new DCOM Lockdowntechnique globally until we understood what exactly triggered themitigation/crash and have a fix for it in place. This DCOM Lockdownmitigation is a sub-mitigation of the Lockdown family that has not yet beenofficially announced/release and we will only disable this sub-mitigation. Allother Lockdown mitigations will remain active.

    All of your Endpoints should receive the today. Once the Endpoints received theupdate, the following registry keys should switch to 0:

    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos EndpointDefense\EndpointFlags"
    "hmpa.lockdownmemory.v2.enforce"="0"
    "hmpa.lockdownmemory.v2.silent"="0"

    We recommend to ensure to remove any Exploit Mitigaiton Exclusions forOutlook.exe that had been set while the issue was present. Also, the ThreatProtection policy setting 'Protect office applications' should be kept enabledto retain full protection.

    Your issue has been escalated to our development team with the above referencenumber. Issues are prioritised based on severity and customer impact. Iwill get back to you with an update on the investigation process by February9th or earlier if Development shares any feedback.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-02-02T16:56:41+00:00

    Assuming you are using Sophos, you can add the exceptions listed previously in this thread - OR - try removing the "Insights" add-in from Outlook.  I had 4 workstations crashing due to the problem in this thread and removing Insights addon fixed all 4 w/o having to add the exceptions to Sophos.

    Thanks for answering, I do not have an "Insights" plugin.
    And I do not have a Sophos system.
    Do you have any more solutions?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-02-02T16:15:34+00:00

    Assuming you are using Sophos, you can add the exceptions listed previously in this thread - OR - try removing the "Insights" add-in from Outlook.  I had 4 workstations crashing due to the problem in this thread and removing Insights addon fixed all 4 w/o having to add the exceptions to Sophos.

    Was this answer helpful?

    0 comments No comments