Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x00000132

RESOURCE_OWNER_POINTER_INVALID 0x00000132 and lock ownership crashes

11 min read Updated October 5, 2026 Windows Crashes & Boot Recovery

Fix it now

These four stops are lock accounting failures: an invalid resource owner pointer, a resource released by a thread that never owned it, a thread terminated with AutoBoost lock entries still held, or a thread that exited with an asynchronous procedure call pending. On a virtualisation host the culprit is nearly always a file system filter driver.

Run these in an elevated Command Prompt on the host

fltmc filters
verifier /querysettings
  1. Confirm the host is keeping dumps. In System Properties, Advanced, Startup and Recovery, set debugging information to Automatic or Kernel memory dump.
  2. Open the newest dump in the Windows debugger and run !analyze -v. Note the module it names; that name is the whole point of the exercise.
  3. Match every third-party filter in the fltmc filters output to a product you know is installed. Antivirus, backup, encryption and data loss prevention agents all appear here.
  4. Check the named driver against its vendor’s supported platform list for the exact Windows Server build you are running, and update it.
  5. Where two products provide overlapping filters, remove one with the vendor’s own uninstaller, reboot, and confirm with fltmc filters that the filter has actually gone.

For 0x00000020 read parameter 2, the thread’s APC disable count. Microsoft states that a negative value means a driver disabled APCs without re-enabling them and a positive value means the reverse, which is the fastest route to the offending code path.

If the host is stable after updating or removing the driver the dump named, you are done. If it is not, the next section explains what the kernel was checking and which of the four codes you have.

Why it happens

Windows uses executive resources to arbitrate shared access to kernel structures. A resource records which thread owns it, whether that ownership is shared or exclusive, and who is waiting. Alongside them the kernel runs AutoBoost, which tracks lock ownership so that a thread holding a lock can be given a temporary priority lift when something more important is waiting on it. Both mechanisms depend on ownership records that describe reality.

Each of these four stops is the moment a record stopped describing reality. 0x00000132 says an invalid resource owner pointer was supplied, and its parameters hand you the resource, its owner table, the current thread and the pointer that was wrong. 0x000000E3 is blunter: a thread tried to release a resource it did not own. 0x00000153 says a thread was terminated before it had freed all its AutoBoost lock entries, which the documentation attributes to a thread relying on another thread to release its lock, or to inconsistent flags passed to the lock package. 0x00000020 says an asynchronous procedure call was still pending when a thread exited.

The kernel cannot carry on from any of them. Ownership records are what guarantee two pieces of code are not modifying the same structure at once, so continuing on records known to be wrong is worse than stopping. That is why there is no repair to apply on the machine: the fix is always to identify the driver that broke the pairing.

They cluster on virtualisation hosts for a structural reason. A host runs very few applications but a great many filter drivers, all intercepting file and storage operations at high volume against cluster shared volumes and multi-terabyte virtual disk files. That is a workload most vendors test less thoroughly than a file server, and it is where the bugs surface.

A filter driver that predates the Windows build

You have this one if The analysis names a third-party driver older than the Windows Server release on the host, or the host was upgraded recently and the agent was not.

  1. Find the driver’s version from the .sys file’s properties and its vendor from the filter name in fltmc filters.
  2. Check the vendor’s compatibility statement for your exact Windows Server release and build.
  3. Upgrade the agent to a version the vendor supports on that build.
  4. Where the vendor does not support the build at all, that is your answer. No configuration bridges that gap.

Two products competing in the same path

You have this one if fltmc filters lists two antivirus minifilters, or an antivirus and a backup filter at adjacent altitudes, and the stops began when the second product was deployed.

  1. Decide which product owns which job on this host and remove the other properly, with its own removal tool.
  2. Apply both vendors’ documented exclusions for virtualisation: cluster shared volume paths, virtual disk and checkpoint files, and the cluster database.
  3. Retest through a full backup cycle before declaring it fixed.

Two real-time scanning engines is not twice the protection. It is two sets of filters interleaving in a path neither vendor tested against the other.

Changed block tracking or snapshot handling in a backup agent

You have this one if Stops line up with backup jobs, snapshot creation or snapshot removal, and stop when backups are paused.

  1. Correlate the crash timestamps with the backup schedule. If they match, you have your candidate.
  2. Update the backup agent including its kernel components, which some products ship separately from the management agent.
  3. As a diagnostic, disable changed block tracking and run a full backup to see whether the host stays up.
  4. Send the dump to the backup vendor. A lock ownership fault in their driver is theirs to fix.

A hardware driver or a genuine Windows defect

You have this one if The analysis names a storage, RAID or multipath driver, or only Microsoft binaries appear on a fully patched host with third-party agents removed.

  1. For a hardware driver, match firmware and driver to the vendor’s tested combination and apply it identically on every node.
  2. For Microsoft binaries, install the latest cumulative update. Faults of this kind are often fixed quietly in servicing.
  3. Then open a support case with the dump. This is the one branch where you should stop changing things and hand it over.

Full reference

Reading the four codes apart

Stop code Name What it states
0x00000132 RESOURCE_OWNER_POINTER_INVALID An invalid resource owner pointer was supplied. Parameters: the resource, its owner table, the current thread, the owner pointer
0x000000E3 RESOURCE_NOT_OWNED A thread tried to release a resource it did not own. Parameters: the resource address, the thread address, the owner table
0x00000153 KERNEL_LOCK_ENTRY_LEAKED_ON_THREAD_TERMINATION A thread was terminated before freeing all its AutoBoost lock entries. Parameter 3 says how the entry was wrong, including a residual boost
0x00000020 KERNEL_APC_PENDING_DURING_EXIT An APC was still pending when a thread exited. Parameter 2 is the APC disable count, parameter 3 the IRQL

Parameter 2 of 0x00000020 is the one to read first on any of these. The count is decremented when a driver calls KeEnterCriticalRegion, FsRtlEnterFileSystem or acquires a mutex, and incremented when it calls the matching KeLeaveCriticalRegion, KeReleaseMutex or FsRtlExitFileSystem. Because those calls should always pair, the count should be zero at thread exit. A non-zero value tells you which half of the pair a driver skipped.

Working out which filters are loaded

Command Purpose
fltmc filters Lists the loaded file system minifilters with their altitudes
!analyze -v The debugger command that performs the initial bugcheck analysis and names the faulting module
verifier /standard /driver a.sys b.sys Enables the standard verification options against a named list of drivers, from the next boot
verifier /querysettings Shows what will be verified after the next boot
verifier /reset Clears all Driver Verifier settings so nothing is verified after the next boot

Driver Verifier deliberately bugchecks the machine on the first violation it finds. Enable it for a small, named set of third-party drivers only, out of hours, and be certain you can reach Safe Mode to run verifier /reset before you start.

Removing an agent properly

  1. Take the host out of service and drain its virtual machines first. A stop during removal is not unusual.
  2. Use the vendor’s dedicated removal utility rather than Programs and Features. A normal uninstall commonly leaves the minifilter registered.
  3. Reboot, then run fltmc filters and confirm the filter is absent rather than merely idle.
  4. Only then install whatever is replacing it, and confirm the replacement’s filter appears where you expect.

When the filter list is clean and it still stops

  • Check the storage path. A multipath, RAID or host bus adapter driver mismatched against its firmware produces exactly this class of fault under load, and the dump names the module.
  • Apply the latest cumulative update to the host before opening a case. Lock accounting defects are routinely fixed in servicing without a public note.
  • Compare nodes. If one node in a cluster stops and the others do not, diff their driver versions before you diff anything else.
  • Keep every dump. A single dump gives you one module name; three dumps that all name the same module give you a support case the vendor cannot deflect.

When a licence is the actual fix

Where the dump names an endpoint or backup driver that the vendor no longer builds for your Windows Server version, no configuration change will fix it. You need an agent still developed and tested against the build in front of you, and very often that is a newer version of what you already own, at no cost. Microsoft Defender Antivirus is included with Windows Server and is supported on host operating systems, so if central policy and reporting are not requirements, removing the failing product and leaving Defender in place is a legitimate outcome. Where you do need managed policy, tuned exclusions and reporting across several hosts, Bitdefender GravityZone Business Security is one of the products we supply, and we will check its current supported platform list against your Windows Server version and roles before you commit. Be clear about what the licence does: getting onto a supported, maintained agent is what removes this class of fault, and the licence is only the means.

Every code this article covers

Code What it points at Source
0x00000132 RESOURCE_OWNER_POINTER_INVALID: an invalid resource owner pointer was supplied Microsoft Learn
0x000000E3 RESOURCE_NOT_OWNED: a thread tried to release a resource it did not own Microsoft Learn
0x00000153 KERNEL_LOCK_ENTRY_LEAKED_ON_THREAD_TERMINATION: a thread was terminated before it had freed all its AutoBoost lock entries Microsoft Learn
0x00000020 KERNEL_APC_PENDING_DURING_EXIT: an asynchronous procedure call was still pending when a thread exited Microsoft Learn

Confirm the fix worked

  1. Run the host through a complete backup cycle and a full business day without a stop.
  2. Run fltmc filters and confirm the filter set is what you intended, with no leftovers from a removed product.
  3. Confirm the agent you updated reports its new version in its own management console.
  4. Confirm no new dump has appeared in the Windows folder or its Minidump subfolder since the change.
  5. Run verifier /querysettings and confirm nothing is left under verification.

Questions people ask about this

Do I need special tools to read the dump?

The Windows debugger is a free download from Microsoft and !analyze -v is a single command. You only need the module name it reports. Most endpoint and backup vendors will also read a dump for you as part of a support case.

Should I just uninstall the antivirus and leave it off?

Not as a permanent answer, but removing it as a diagnostic step is entirely reasonable. Microsoft Defender Antivirus is present on Windows Server and provides real protection, so removing a third-party agent leaves the host covered rather than exposed.

Why does only the host stop and never the guests?

Filter drivers on the host run in the parent partition and see every operation against the virtual disks. The guests have their own stacks and never touch the failing driver. That asymmetry is itself a clue about where to look.

Is 0x00000153 different from the other three?

Slightly. It is specifically about AutoBoost lock entries not being freed before a thread ended, and Microsoft names two causes: a thread relying on another thread to release its lock, or inconsistent flags passed to the lock package. Both are driver bugs, but it narrows the search to code using AutoBoost-tracked locks.

Will buying a different security product fix this?

Only if the current one is genuinely unsupported on your build and cannot be updated. Read the dump first and find out which case you are in, because very often the fix is a newer version of what you already have.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Windows RE update fails with 0x80070643 – recovery partition too small Free Fix NETWORK_BOOT_DUPLICATE_ADDRESS 0x000000BC and PXE boot failures on WDS License Error There was a problem resetting your PC – error 0x80070003 in Reset This PC Free Fix DRIVER_IRQL_NOT_LESS_OR_EQUAL 0x000000D1 and IRQL_NOT_LESS_OR_EQUAL 0x0000000A
โ† Back to Knowledge Base