Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x00000050

PAGE_FAULT_IN_NONPAGED_AREA 0x00000050 – what the stop code really means

12 min read Updated October 5, 2026 Windows Crashes & Boot Recovery

Fix it now

0x00000050 means invalid system memory was referenced – typically an address that is wrong, or one pointing at memory that has already been freed. Microsoft’s own cause list names a faulty driver or system service, antivirus software, a corrupted NTFS volume and faulty hardware, in that order.

Run these in an elevated Command Prompt; chkdsk will ask to run at the next restart

sfc /scannow
chkdsk C: /f /r
fltmc
  1. Get parameters 2 and 4 from the BugCheck event in the System log or from !analyze -v on the newest dump. Parameter 2 says whether it was a read (0), a write (2) or an execute (10) on x64 and x86; parameter 4 says what kind of page fault it was.
  2. If the dump names a third-party driver, that is where to start. Get the current build from the hardware vendor rather than letting Windows Update choose one.
  3. Microsoft names antivirus software explicitly among the causes. Disable the third-party agent and confirm whether the crash stops – that test is the diagnosis, not a fix.
  4. Run chkdsk C: /f /r. A corrupted NTFS volume is a documented cause and the check is cheap.
  5. Test memory. Type Windows Memory Diagnostics at Start, run the extended test mix, and read the results in the System log.

driverquery /si /fo table gives you a signed-driver inventory, and pnputil /enum-drivers lists the installed driver packages by their oem names, which is what you need to remove one cleanly.

If the machine is stable after the driver or volume repair, stop here. The next section explains how to read the parameters and which sibling codes change the answer.

Why it happens

Nonpaged kernel memory is memory the system has promised will always be resident. Code running at a raised IRQL relies on that promise, because it cannot take a page fault – there is no safe point at which to wait for a disk read. 0x00000050 is what happens when that promise turns out to be false: a reference was made to an address that is not backed by anything valid. Microsoft’s description is deliberately plain – the memory address is wrong, or it is pointing at freed memory.

The parameters are the whole diagnostic and they are not on the stop screen. Parameter 1 is the address referenced. Parameter 2 says what was being done to it: on current x64 and x86 builds, 0 is a read, 2 is a write and 10 is an execute; on Arm the values are 0, 1 and 8. Parameter 3 is the address that made the reference, where it is known. Parameter 4 is the type of page fault, and it is the most informative of the four.

That parameter 4 table separates cases that look identical otherwise. 0x0 means the address sits on a page table entry marked free – a use-after-free. 0x2 means there is no valid active page table entry at all. 0x3 means a session space address was referenced from a process with no session. 0x4 means a non-canonical, illegal virtual address, which usually means a pointer was built from something that was not a pointer. 0xF means kernel-mode code touched a user-mode address where that is not allowed.

Two codes in this family are commonly confused with 0x50 and should not be. 0x000000C5 is not a pool corruption detector; its published description is the same as 0x000000D0 – invalid memory accessed at too high an IRQL, almost certainly because a driver corrupted the system pool – and the only thing that separates the two is allocation size, with 0xC5 the small case. 0x000000D8 and 0x000000DA are about system page table entries rather than pool at all.

A driver referencing memory it no longer owns

You have this one if Parameter 4 is 0x0 or 0x2, and the dump names a third-party .sys file.

  1. Take the current driver from the hardware vendor’s own support page for the exact model.
  2. If the crash started after a driver update, roll back in Device Manager, or install the previous long-lived branch.
  3. Remove the package properly rather than disabling the device: pnputil /enum-drivers then pnputil /delete-driver <oem#.inf> /uninstall.
  4. On a test machine, run the standard Driver Verifier set against that driver to confirm it is the writer.

Antivirus or endpoint software

You have this one if The named module belongs to a security product, or the crashes cluster around file access. Microsoft names antivirus software in the cause list for this code.

  1. Disable the third-party agent and confirm whether the error stops. Microsoft’s documented step is exactly this test.
  2. If it does, contact the vendor about an update, or move to a build they support on your Windows version.
  3. Where the product was uninstalled but the filter remains, use the vendor’s removal utility and confirm with fltmc.
  4. Only one real-time scanner should own the file system filter path. Microsoft Defender takes over again when a registered third-party product is removed.

A corrupted NTFS volume

You have this one if Crashes come with storage errors in the System log, or the machine has been through a hard power loss.

  1. Run chkdsk C: /f /r. Microsoft names a corrupted NTFS volume as a cause of this code and this as the remedy.
  2. chkdsk has to lock the volume, so on the system drive it offers to run at the next restart instead; the /r pass takes hours on a large disk.
  3. Read the drive’s own health data with the manufacturer’s tool afterwards.
  4. If the volume keeps returning errors, treat the drive as suspect and image it.

Failing memory or another hardware fault

You have this one if The named module changes between crashes and the codes vary – 0x50 one time, 0x1A or 0x1E the next.

  1. Run Windows Memory Diagnostics with the extended test mix and read the results in the System log.
  2. If hardware was added recently, remove it and see whether the crash follows.
  3. Return firmware to stock settings, including memory profiles, before drawing conclusions.
  4. Run the diagnostics the system manufacturer supplies, which usually cover more than memory.

Full reference

The parameters, in the form you will actually use them

Parameter What it holds
1 The memory address that was referenced
2 The operation: 0 read, 2 write, 10 execute on x64 and x86; 0, 1 and 8 on Arm
3 The address that referenced the memory, if known
4 The type of page fault – see the table below
Parameter 4 Name What it means
0x0 NONPAGED_BUGCHECK_FREED_PTE The address is on a page table entry marked as free
0x2 NONPAGED_BUGCHECK_NOT_PRESENT_PAGE_TABLE There is no valid active page table entry for the address
0x03 NONPAGED_BUGCHECK_WRONG_SESSION A session space address was referenced from a process with no session
0x04 NONPAGED_BUGCHECK_VA_NOT_CANONICAL A non-canonical, illegal virtual address was referenced
0xF NONPAGED_BUGCHECK_USER_VA_ACCESS_INCONSISTENT Kernel-mode code accessed a user-mode address where that is not allowed

The siblings, and why they are not the same fault

Code Published meaning What to do differently
0x00000050 Invalid system memory referenced Read parameter 4 and work from the cause list
0x000000C5 Invalid memory at too high an IRQL; a driver corrupted the system pool, allocation smaller than PAGE_SIZE Use special pool, not chkdsk
0x000000D8 No more system page table entries remain Parameter 1 points at the name of the driver that consumed the most
0x000000DA A page table entry routine was used improperly Parameter 1 names the violation – duplicate or mismatched mapping frees, MDL misuse, ownership errors

When the machine is running out of page table entries

0x000000D8 is the one code here with a name written on it. Parameter 1 points at the name of the driver that consumed the most system PTEs, while the call stack shows the driver that happened to be asking when the last one ran out. Those are frequently different, and the first is the one to act on. It is a slow failure that shows up after long uptime, so a machine that only crashes after weeks is a candidate.

0x000000DA is a misuse rather than an exhaustion: a PTE routine used in an improper way, with parameter 1 naming which – duplicate frees of a mapping, mismatched frees, MDL misuse, and mapping ownership errors. It is also what 0x000000DB turns into when you set TrackPtes to 3, so if you enabled that diagnostic on purpose, this is the result you were after.

Getting a clean answer out of a driver replacement

  1. Record the current driver version before you change anything, so a rollback is possible.
  2. Take the replacement from the hardware vendor’s page for that exact model, not from a driver aggregator.
  3. On laptops, prefer the notebook manufacturer’s build where they publish one – it carries the panel and switchable-graphics customisation generic packages do not.
  4. Remove the old package with pnputil /delete-driver <oem#.inf> /uninstall rather than leaving it available for Windows to reinstall.
  5. Restart twice and run the workload that crashed before calling it fixed.

Checks worth doing before you conclude it is hardware

  • sfc /scannow, then DISM /Online /Cleanup-Image /RestoreHealth if it reports files it could not repair.
  • The System log around each crash, for storage or device errors that arrive just before the bug check.
  • Device Manager for anything marked with an exclamation point.
  • fltmc for filters belonging to products that are no longer installed.
  • Whether more than one real-time scanner is installed. Microsoft names antivirus among the causes of this specific code, which is unusual and worth taking at face value.

When a licence is the actual fix

Where the trail ends at a security agent that is no longer receiving builds – because the licence lapsed and the console can no longer push updates – the fix is a supported build rather than an exclusion or a registry change. Removing the agent and relying on Microsoft Defender is free, supported, and adds no third-party filter to the stack. Where central policy, device control and reporting across a fleet are required, a current licence restores update delivery so the kernel components track the Windows builds you are running. Arco supplies Kaspersky Endpoint Security for Business and can check which seat count and term fits the estate you actually run.

Every code this article covers

Code What it points at Source
0x00000050 PAGE_FAULT_IN_NONPAGED_AREA: invalid system memory has been referenced, typically an address that is wrong or one pointing at freed memory. Documented causes are a faulty system service or driver, antivirus software, a corrupted NTFS volume and faulty hardware Microsoft Learn
0x000000C5 DRIVER_CORRUPTED_EXPOOL: the system accessed invalid memory at a process IRQL that was too high, almost certainly because a driver corrupted the system pool. This code, rather than 0x000000D0, results when the corrupted allocation was smaller than PAGE_SIZE Microsoft Learn
0x000000D8 DRIVER_USED_EXCESSIVE_PTES: there are no more system page table entries remaining. Parameter 1 points at the name of the driver that consumed the most, while the call stack shows the driver that bug checked Microsoft Learn
0x000000DA SYSTEM_PTE_MISUSE: a page table entry routine was used in an improper way. Parameter 1 identifies the violation, covering duplicate and mismatched mapping frees, MDL misuse and mapping ownership errors Microsoft Learn

Confirm the fix worked

  1. chkdsk C: /f /r completes with no unrecoverable errors reported.
  2. sfc /scannow reports no integrity violations.
  3. Windows Memory Diagnostics passes an extended run, with the result recorded in the System log.
  4. The workload that used to crash the machine runs to completion twice.
  5. fltmc lists only filters belonging to products that are installed and supported.

Questions people ask about this

The blue screen named a driver. Is that the guilty one?

Usually, but not always. It is the module that was running when the invalid reference happened, which can also mean it was the victim of memory another driver damaged. If replacing it changes nothing, run the standard Driver Verifier set against your third-party drivers on a test machine.

Is it really worth disabling antivirus?

As a test, yes. Microsoft names antivirus software in the published cause list for this specific code and its documented step is to disable the program and confirm whether the error stops. Turning it back on afterwards is part of the test.

How do I read parameter 2?

On current x64 and x86 Windows, 0 is a read, 2 is a write and 10 is an execute. On Arm they are 0, 1 and 8. Before Windows 1507 the x64 and x86 values were 0 for read and 1 for write, which is why old notes disagree with new dumps.

Does more RAM help?

Only if the memory you have is faulty. This is a reference to an invalid address, not a shortage, so adding capacity changes when the crash happens rather than whether it happens.

Do I need to reinstall Windows?

Almost never. Between sfc /scannow, chkdsk /f /r, a driver replacement and a memory test you have covered every cause Microsoft publishes for this code. A reinstall fixes it by side effect and costs you everything on the disk.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix MEMORY_MANAGEMENT 0x0000001A and PFN_LIST_CORRUPT 0x0000004E blue screens Free Fix Domain controller will not boot – 0xC00002E2 directory services init failure License Error FLTMGR_FILE_SYSTEM 0x000000F5 – antivirus minifilter crashes the kernel Free Fix DISM RestoreHealth fails with 0x800F081F or 0x80073712 during recovery
โ† Back to Knowledge Base