Why would an antivirus program push driver updates through definition updates aka Crowdstrike Falcon? This sort of thing seems inevitable if it bypasses change management controls.
Well, the answer seems to be Crowdstrike's oopsie was not a stealth driver update. Rather, the company is stating today that there was some rather unfortunate programming in a new definition file.
https://www.crowdstrike.com/blog/technical-details-on-todays-outage/
The definition updates (channel file updates) reside in C:\Windows\System32\drivers\CrowdStrike. And the file names end in .sys.
Ok then.