Fix it now
A user-mode process the kernel treats as critical has ended, and Windows stopped rather than continue without it. Microsoft names two causes: a third-party driver, service or application, and mismatched system files – most often after a restore from backup that skipped files it judged to be in use.
diskpart
list volume
exit
sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows
dism /Image:D:\ /Cleanup-Image /RestoreHealth
dism /Image:D:\ /Get-Packages /Format:Table
- Get into the recovery environment: hold Shift while choosing Restart, or interrupt startup with the power button three times, then Troubleshoot, Advanced options, Command Prompt.
- Find the real Windows volume with
diskpartandlist volumebefore running anything. The recovery environment reassigns letters and it is rarely C:. - Read the package list for one installed on the day the failures began, and remove it with
dism /Image:D:\ /Remove-Package /PackageName:<full package name>. Only .cab packages can be removed this way; .msu files cannot. - If a package is stuck in Install Pending, clear it with
dism /Image:D:\ /Cleanup-Image /RevertPendingActions, which Microsoft supports only against an offline image. - Restart. If it still stops, go to Advanced options, Startup Settings and boot Safe Mode, then remove whatever was installed most recently.
On a BitLocker-protected machine none of this is available without the 48-digit recovery key. Retrieve it from the Microsoft account, Entra ID or Active Directory before you start.
If the machine reaches the desktop twice from cold, you are done. If not, the next section explains what the kernel is protecting and how to tell the two documented causes apart.
Why it happens
Windows runs a small group of processes the rest of the system assumes will always be there. Microsoft names them: csrss.exe, wininit.exe, logonui.exe, smss.exe, services.exe, conhost.exe and winlogon.exe. They run in user mode like any other program, but the kernel marks them critical, because everything already running holds handles into them and there is no supported way to restart one mid-session.
0xC000021A is published as WINLOGON_FATAL_ERROR: the Winlogon process terminated unexpectedly. Microsoft’s stated cause is that a user-mode subsystem such as Winlogon or the Client Server Run-Time Subsystem has been fatally compromised and security can no longer be guaranteed, so the operating system switches to kernel mode and stops. It is one of the few cases where the failure of a user-mode service shuts the machine down.
0x000000EF is the numbered bug check for the same class of event: a critical system process terminated because its state was corrupted or damaged. Its parameters are worth reading correctly, because they are commonly misquoted. Parameter 1 is the process object, not a name. Parameter 2 is what tells you what died – 0 for a process, 1 for a thread. 0x000000F4 is its close relative, a process or thread crucial to system operation exiting unexpectedly, and it is the more helpful of the two on screen because parameter 3 is the process image file name.
The cause most articles miss is Microsoft’s second one. Mismatched system files produce 0xC000021A, and the situation Microsoft describes is restoring a hard disk from a backup where the backup program skipped restoring system files it determined were in use. If this machine was recently restored rather than recently updated, that is where to look, and no amount of update removal will help.
The last quality update left the system inconsistent
You have this one if The machine restarted to finish installing updates and never came back. The DISM package list shows an install date matching the day the failures began.
- In the recovery environment choose Troubleshoot, Advanced options, Uninstall Updates and remove the latest quality update.
- If that menu fails, use
dism /Image:D:\ /Get-Packages /Format:Tableand find the newest package whose state is Installed or Install Pending. - Remove it with
dism /Image:D:\ /Remove-Package /PackageName:<full package name>, then restart.
A package stuck in Install Pending is worth clearing first with dism /Image:D:\ /Cleanup-Image /RevertPendingActions. Microsoft states it is not supported on a running system or against a Windows PE or Windows RE image, so it must target the offline Windows image.
The machine was restored from a backup
You have this one if The failure followed a restore rather than an update, and the machine had been working normally until that restore.
- Check whether the backup product has a newer version; Microsoft’s advice here is to look for an updated build of the backup or restore program.
- Repair the mismatch rather than chasing updates: offline
sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows, thendism /Image:D:\ /Cleanup-Image /RestoreHealth. - If DISM cannot find a source, mount installation media of the same build and add
/Source:WIM:E:\sources\install.wim:1 /LimitAccess. - If the repair will not complete, restore again with a product that does not skip in-use system files, or rebuild.
A third-party driver or service is loading and failing
You have this one if Safe Mode starts cleanly and a normal boot does not. The trouble began after installing or updating endpoint protection, a backup agent, disk encryption or a virtual drive product.
- Boot Safe Mode through Advanced options, Startup Settings.
- Uninstall the product from Installed apps, using the vendor’s removal tool where one exists rather than deleting files.
- If Safe Mode is also unreachable, list drivers offline with
dism /Image:D:\ /Get-Drivers /Format:Tableand remove the third-party one withdism /Image:D:\ /Remove-Driver /Driver:oemNN.inf.
Never remove a driver whose provider is Microsoft, and never a storage or chipset driver. Removing a boot-critical driver makes the image unbootable, and the recovery environment will not put it back for you.
System files or the component store are damaged
You have this one if Offline SFC reports corrupt files it could not repair, or the crash followed a power cut, a failed update or a disk that filled up.
- Run the offline SFC command and read the summary line it prints.
- Follow it with
dism /Image:D:\ /Cleanup-Image /RestoreHealth. - Run
chkdsk D: /fand let it finish, then repeat the SFC pass. The two tools depend on each other in that order.
Full reference
Reading the four codes
| Code | Name | Published meaning | Most useful parameter |
|---|---|---|---|
0xC000021A |
WINLOGON_FATAL_ERROR | The Winlogon process terminated unexpectedly | Parameter 1 is a string identifying the problem; parameter 2 the error code |
0x000000EF |
CRITICAL_PROCESS_DIED | A critical system process terminated | Parameter 2: 0 for a process, 1 for a thread |
0x000000F4 |
CRITICAL_OBJECT_TERMINATION | A process or thread crucial to system operation exited or was terminated | Parameter 3 is the process image file name |
0x0000005A |
CRITICAL_SERVICE_FAILED | Microsoft publishes the name only, and notes it appears very infrequently | – |
0x000000F4 is the one to hope for, because it names the image file. If you have a dump for any of the others, the analysis extension will resolve the process object in parameter 1 to a name; without one, the pattern of when the failure occurs is what you have.
Narrowing it before you start repairing
| What you observe | Where the fault almost certainly is |
|---|---|
| The first failure came right after a restart that installed updates | The last cumulative or servicing stack update |
| The first failure came right after a restore from backup | Mismatched system files the backup product skipped |
| Safe Mode starts, a normal boot does not | A third-party driver or service Safe Mode does not load |
| The stop happens at or just after sign-in, or only for one account | A damaged user profile or registry hive |
| Stop codes vary between attempts, with disk or memory errors logged | Failing hardware, not software |
Working offline without breaking anything
- Establish the Windows volume letter every single time. Recovery reassigns letters between boots, so a letter that was right an hour ago may not be now.
- Run the read-only commands first –
/Get-Packages,/Get-Drivers,sfcwith/verifyonlywhere available – and write down what you find before you change anything. - Make one change, then restart. Two changes at once turns a diagnosis into a guess.
- Keep a note of every package and driver removed, so the machine can be returned to a supported state afterwards.
- Reapply the updates you removed once the machine is stable, one at a time, so you know which one was the problem.
When a profile rather than the system is broken
If the stop arrives at or just after the sign-in screen, and other accounts sign in normally, the system is intact and one profile is not. System Restore from the recovery environment is the cleanest route because it replaces the registry hives as part of the restore. Where only one profile is affected, sign in with another administrator account and create a fresh profile rather than repairing the broken one – it is faster and it leaves you with a known state.
Before you uninstall updates, remove drivers or run System Restore, make sure you can unlock the drive. On a BitLocker-protected machine the recovery environment asks for the 48-digit recovery key, and without it none of these steps exist. Retrieve it from the Microsoft account, Entra ID or Active Directory first.
If the stop code changes between attempts, stop repairing software. Run mdsched.exe from a working session, check drive health with the manufacturer’s utility, and on a server read the management controller log for memory and storage faults before going further.
When nothing offline works
An in-place repair upgrade rebuilds every Windows component while leaving applications, settings and data alone. Mount media matching the current edition and build, run setup from within Windows, and choose to keep files and apps. It needs the machine to start far enough to run setup, which is exactly what this fault often prevents – so it is the step after Safe Mode, not before it. A reset comes after that, and a clean install after that.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC000021A |
WINLOGON_FATAL_ERROR: the Winlogon process terminated unexpectedly. Raised when a user-mode subsystem such as Winlogon or CSRSS has been fatally compromised; mismatched system files after a restore from backup are also a documented cause | Microsoft Learn |
0x000000EF |
CRITICAL_PROCESS_DIED: a critical system process terminated because its state was corrupted or damaged. Parameter 1 is the process object; parameter 2 is 0 for a process and 1 for a thread | Microsoft Learn |
0x000000F4 |
CRITICAL_OBJECT_TERMINATION: a process or thread crucial to system operation has unexpectedly exited or been terminated. Parameter 3 is the process image file name | Microsoft Learn |
0x0000005A |
Microsoft publishes the name CRITICAL_SERVICE_FAILED and nothing further – no description, cause or resolution – and notes the bug check appears very infrequently | Microsoft Learn |
Confirm the fix worked
- Restart twice, including one full power off rather than a restart, and confirm both reach the desktop.
sfc /scannowfrom an elevated prompt in the running system reports no integrity violations.- No new BugCheck event with ID 1001 appears in the System log after the repair.
C:\Windows\Minidumpgains no new dump files after a day of normal use.- Any update you removed reinstalls cleanly, or you know which one to keep held back and why.
Questions people ask about this
Will any of this delete my files?
No. Offline SFC, DISM, chkdsk, uninstalling an update and removing a driver all leave user data alone. System Restore rolls back system files, drivers and the registry and can remove applications installed after the restore point, but it does not touch documents.
Does fixing this cost anything?
No. Every tool here ships with Windows and the recovery environment is already on the machine. Nothing about this error indicates a licensing problem. If a disk or memory module turns out to be dead you will be buying hardware, which is a separate matter.
Safe Mode works fine. What does that tell me?
That Windows itself is intact. Safe Mode loads only Microsoft’s core drivers and a minimal set of services, so the failing component is outside that set: an endpoint agent, a backup filter, a storage or graphics driver, or a service that starts automatically.
It started right after I restored the machine from backup.
Then look there first rather than at updates. Microsoft names mismatched system files as a cause of 0xC000021A, and describes exactly this situation – a backup program that skipped restoring system files it judged to be in use. Repair the image with offline SFC and DISM, and check whether the backup product has a newer build.
Why does removing an update need DISM rather than the usual tools?
Because the machine will not start, so nothing in Windows is available to do it. DISM against an offline image is the supported way to list and remove packages from outside. Note that only .cab packages can be removed this way; .msu files cannot.
