Fix it now
0x00000050 means invalid system memory was referenced – typically an address that is wrong, or one pointing at memory that has already been freed. Microsoft’s own cause list names a faulty driver or system service, antivirus software, a corrupted NTFS volume and faulty hardware, in that order.
sfc /scannow
chkdsk C: /f /r
fltmc
- Get parameters 2 and 4 from the BugCheck event in the System log or from
!analyze -von the newest dump. Parameter 2 says whether it was a read (0), a write (2) or an execute (10) on x64 and x86; parameter 4 says what kind of page fault it was. - If the dump names a third-party driver, that is where to start. Get the current build from the hardware vendor rather than letting Windows Update choose one.
- Microsoft names antivirus software explicitly among the causes. Disable the third-party agent and confirm whether the crash stops – that test is the diagnosis, not a fix.
- Run
chkdsk C: /f /r. A corrupted NTFS volume is a documented cause and the check is cheap. - Test memory. Type Windows Memory Diagnostics at Start, run the extended test mix, and read the results in the System log.
driverquery /si /fo table gives you a signed-driver inventory, and pnputil /enum-drivers lists the installed driver packages by their oem names, which is what you need to remove one cleanly.
If the machine is stable after the driver or volume repair, stop here. The next section explains how to read the parameters and which sibling codes change the answer.
Why it happens
Nonpaged kernel memory is memory the system has promised will always be resident. Code running at a raised IRQL relies on that promise, because it cannot take a page fault – there is no safe point at which to wait for a disk read. 0x00000050 is what happens when that promise turns out to be false: a reference was made to an address that is not backed by anything valid. Microsoft’s description is deliberately plain – the memory address is wrong, or it is pointing at freed memory.
The parameters are the whole diagnostic and they are not on the stop screen. Parameter 1 is the address referenced. Parameter 2 says what was being done to it: on current x64 and x86 builds, 0 is a read, 2 is a write and 10 is an execute; on Arm the values are 0, 1 and 8. Parameter 3 is the address that made the reference, where it is known. Parameter 4 is the type of page fault, and it is the most informative of the four.
That parameter 4 table separates cases that look identical otherwise. 0x0 means the address sits on a page table entry marked free – a use-after-free. 0x2 means there is no valid active page table entry at all. 0x3 means a session space address was referenced from a process with no session. 0x4 means a non-canonical, illegal virtual address, which usually means a pointer was built from something that was not a pointer. 0xF means kernel-mode code touched a user-mode address where that is not allowed.
Two codes in this family are commonly confused with 0x50 and should not be. 0x000000C5 is not a pool corruption detector; its published description is the same as 0x000000D0 – invalid memory accessed at too high an IRQL, almost certainly because a driver corrupted the system pool – and the only thing that separates the two is allocation size, with 0xC5 the small case. 0x000000D8 and 0x000000DA are about system page table entries rather than pool at all.
A driver referencing memory it no longer owns
You have this one if Parameter 4 is 0x0 or 0x2, and the dump names a third-party .sys file.
- Take the current driver from the hardware vendor’s own support page for the exact model.
- If the crash started after a driver update, roll back in Device Manager, or install the previous long-lived branch.
- Remove the package properly rather than disabling the device:
pnputil /enum-driversthenpnputil /delete-driver <oem#.inf> /uninstall. - On a test machine, run the standard Driver Verifier set against that driver to confirm it is the writer.
Antivirus or endpoint software
You have this one if The named module belongs to a security product, or the crashes cluster around file access. Microsoft names antivirus software in the cause list for this code.
- Disable the third-party agent and confirm whether the error stops. Microsoft’s documented step is exactly this test.
- If it does, contact the vendor about an update, or move to a build they support on your Windows version.
- Where the product was uninstalled but the filter remains, use the vendor’s removal utility and confirm with
fltmc. - Only one real-time scanner should own the file system filter path. Microsoft Defender takes over again when a registered third-party product is removed.
A corrupted NTFS volume
You have this one if Crashes come with storage errors in the System log, or the machine has been through a hard power loss.
- Run
chkdsk C: /f /r. Microsoft names a corrupted NTFS volume as a cause of this code and this as the remedy. - chkdsk has to lock the volume, so on the system drive it offers to run at the next restart instead; the /r pass takes hours on a large disk.
- Read the drive’s own health data with the manufacturer’s tool afterwards.
- If the volume keeps returning errors, treat the drive as suspect and image it.
Failing memory or another hardware fault
You have this one if The named module changes between crashes and the codes vary – 0x50 one time, 0x1A or 0x1E the next.
- Run Windows Memory Diagnostics with the extended test mix and read the results in the System log.
- If hardware was added recently, remove it and see whether the crash follows.
- Return firmware to stock settings, including memory profiles, before drawing conclusions.
- Run the diagnostics the system manufacturer supplies, which usually cover more than memory.
Full reference
The parameters, in the form you will actually use them
| Parameter | What it holds |
|---|---|
| 1 | The memory address that was referenced |
| 2 | The operation: 0 read, 2 write, 10 execute on x64 and x86; 0, 1 and 8 on Arm |
| 3 | The address that referenced the memory, if known |
| 4 | The type of page fault – see the table below |
| Parameter 4 | Name | What it means |
|---|---|---|
0x0 |
NONPAGED_BUGCHECK_FREED_PTE | The address is on a page table entry marked as free |
0x2 |
NONPAGED_BUGCHECK_NOT_PRESENT_PAGE_TABLE | There is no valid active page table entry for the address |
0x03 |
NONPAGED_BUGCHECK_WRONG_SESSION | A session space address was referenced from a process with no session |
0x04 |
NONPAGED_BUGCHECK_VA_NOT_CANONICAL | A non-canonical, illegal virtual address was referenced |
0xF |
NONPAGED_BUGCHECK_USER_VA_ACCESS_INCONSISTENT | Kernel-mode code accessed a user-mode address where that is not allowed |
The siblings, and why they are not the same fault
| Code | Published meaning | What to do differently |
|---|---|---|
0x00000050 |
Invalid system memory referenced | Read parameter 4 and work from the cause list |
0x000000C5 |
Invalid memory at too high an IRQL; a driver corrupted the system pool, allocation smaller than PAGE_SIZE | Use special pool, not chkdsk |
0x000000D8 |
No more system page table entries remain | Parameter 1 points at the name of the driver that consumed the most |
0x000000DA |
A page table entry routine was used improperly | Parameter 1 names the violation – duplicate or mismatched mapping frees, MDL misuse, ownership errors |
When the machine is running out of page table entries
0x000000D8 is the one code here with a name written on it. Parameter 1 points at the name of the driver that consumed the most system PTEs, while the call stack shows the driver that happened to be asking when the last one ran out. Those are frequently different, and the first is the one to act on. It is a slow failure that shows up after long uptime, so a machine that only crashes after weeks is a candidate.
0x000000DA is a misuse rather than an exhaustion: a PTE routine used in an improper way, with parameter 1 naming which – duplicate frees of a mapping, mismatched frees, MDL misuse, and mapping ownership errors. It is also what 0x000000DB turns into when you set TrackPtes to 3, so if you enabled that diagnostic on purpose, this is the result you were after.
Getting a clean answer out of a driver replacement
- Record the current driver version before you change anything, so a rollback is possible.
- Take the replacement from the hardware vendor’s page for that exact model, not from a driver aggregator.
- On laptops, prefer the notebook manufacturer’s build where they publish one – it carries the panel and switchable-graphics customisation generic packages do not.
- Remove the old package with
pnputil /delete-driver <oem#.inf> /uninstallrather than leaving it available for Windows to reinstall. - Restart twice and run the workload that crashed before calling it fixed.
Checks worth doing before you conclude it is hardware
sfc /scannow, thenDISM /Online /Cleanup-Image /RestoreHealthif it reports files it could not repair.- The System log around each crash, for storage or device errors that arrive just before the bug check.
- Device Manager for anything marked with an exclamation point.
fltmcfor filters belonging to products that are no longer installed.- Whether more than one real-time scanner is installed. Microsoft names antivirus among the causes of this specific code, which is unusual and worth taking at face value.
When a licence is the actual fix
Where the trail ends at a security agent that is no longer receiving builds – because the licence lapsed and the console can no longer push updates – the fix is a supported build rather than an exclusion or a registry change. Removing the agent and relying on Microsoft Defender is free, supported, and adds no third-party filter to the stack. Where central policy, device control and reporting across a fleet are required, a current licence restores update delivery so the kernel components track the Windows builds you are running. Arco supplies Kaspersky Endpoint Security for Business and can check which seat count and term fits the estate you actually run.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x00000050 |
PAGE_FAULT_IN_NONPAGED_AREA: invalid system memory has been referenced, typically an address that is wrong or one pointing at freed memory. Documented causes are a faulty system service or driver, antivirus software, a corrupted NTFS volume and faulty hardware | Microsoft Learn |
0x000000C5 |
DRIVER_CORRUPTED_EXPOOL: the system accessed invalid memory at a process IRQL that was too high, almost certainly because a driver corrupted the system pool. This code, rather than 0x000000D0, results when the corrupted allocation was smaller than PAGE_SIZE | Microsoft Learn |
0x000000D8 |
DRIVER_USED_EXCESSIVE_PTES: there are no more system page table entries remaining. Parameter 1 points at the name of the driver that consumed the most, while the call stack shows the driver that bug checked | Microsoft Learn |
0x000000DA |
SYSTEM_PTE_MISUSE: a page table entry routine was used in an improper way. Parameter 1 identifies the violation, covering duplicate and mismatched mapping frees, MDL misuse and mapping ownership errors | Microsoft Learn |
Confirm the fix worked
chkdsk C: /f /rcompletes with no unrecoverable errors reported.sfc /scannowreports no integrity violations.- Windows Memory Diagnostics passes an extended run, with the result recorded in the System log.
- The workload that used to crash the machine runs to completion twice.
fltmclists only filters belonging to products that are installed and supported.
Questions people ask about this
The blue screen named a driver. Is that the guilty one?
Usually, but not always. It is the module that was running when the invalid reference happened, which can also mean it was the victim of memory another driver damaged. If replacing it changes nothing, run the standard Driver Verifier set against your third-party drivers on a test machine.
Is it really worth disabling antivirus?
As a test, yes. Microsoft names antivirus software in the published cause list for this specific code and its documented step is to disable the program and confirm whether the error stops. Turning it back on afterwards is part of the test.
How do I read parameter 2?
On current x64 and x86 Windows, 0 is a read, 2 is a write and 10 is an execute. On Arm they are 0, 1 and 8. Before Windows 1507 the x64 and x86 values were 0 for read and 1 for write, which is why old notes disagree with new dumps.
Does more RAM help?
Only if the memory you have is faulty. This is a reference to an invalid address, not a shortage, so adding capacity changes when the crash happens rather than whether it happens.
Do I need to reinstall Windows?
Almost never. Between sfc /scannow, chkdsk /f /r, a driver replacement and a memory test you have covered every cause Microsoft publishes for this code. A reinstall fixes it by side effect and costs you everything on the disk.
