Global DEX Findings by ControlUp

Discover real-world application and system stability issues identified through ControlUp’s anonymized global dataset. These findings surface emerging risks, configuration-related failures, and performance anomalies to help IT identify issues earlier, understand impact at scale, and take informed action.
Filter findings







Want to stay on top of new Findings as they’re published?
Subscribe via RSS and get updates automatically.
Latest findings:
January 15, 2026 ID: CUA-2026-001

Organizations running Citrix Workspace should:

  • Identify endpoints running Citrix Workspace client version 25.11.0.161
  • Monitor crash trends related to wfica32.exe to assess user impact
  • Avoid broad production deployment of this version where possible


Online reports

indicate that version 25.11.0.161 has been removed from Citrix’s download channels,
potentially pending replacement with a newer build. Organizations are advised to monitor Citrix
release updates and validate stability before adopting newer versions.

This finding highlights the operational risk associated with newly released client software, particularly components responsible
for session establishment and transport. Even low-severity regressions can have outsized impact in environments that rely heavily
on virtual application and desktop access.

ControlUp will continue monitoring crash activity related to wfica32.exe and update this finding if adoption of
replacement builds changes the observed stability pattern. Community feedback on mitigations, replacement versions, or vendor
guidance can help keep this finding current and actionable.

This finding highlights the operational risk associated with newly released client software, particularly components responsible
for session establishment and transport. Even low-severity regressions can have outsized impact in environments that rely heavily
on virtual application and desktop access.

ControlUp will continue monitoring crash activity related to wfica32.exe and update this finding if adoption of
replacement builds changes the observed stability pattern. Community feedback on mitigations, replacement versions, or vendor
guidance can help keep this finding current and actionable.

This finding highlights the operational risk associated with newly released client software, particularly components responsible
for session establishment and transport. Even low-severity regressions can have outsized impact in environments that rely heavily
on virtual application and desktop access.

ControlUp will continue monitoring crash activity related to wfica32.exe and update this finding if adoption of
replacement builds changes the observed stability pattern. Community feedback on mitigations, replacement versions, or vendor
guidance can help keep this finding current and actionable.

Severity: Low Impacted Organizations: 18
Learn more

November 14, 2025 ID: CUA-2025-007
Organizations using Adobe Creative Cloud should:
  • Review crash logs related specifically to adobecollabsync.exe
  • Identify the exact executable version deployed across affected endpoints
  • Prioritize updating systems running versions 25.1.20918.0 or 25.1.20937.0
  • Apply the latest Adobe Creative Cloud updates, particularly versions 25.1.20997.0 or newer, where crash rates have materially decreased
  • Monitor post-update crash trends to confirm stability improvements
If crashes persist after updating, correlating the issue with specific user profiles, network conditions, or sync configurations may help narrow the scope.

This finding underscores the critical role of background synchronization services, often invisible to users, in modern creative workflows. When these components fail, the impact is felt across teams relying on shared assets and real-time collaboration.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you’re seeing similar Creative Cloud sync issues or have identified effective mitigations, community feedback can help accelerate understanding and resolution.

This finding underscores the critical role of background synchronization services, often invisible to users, in modern creative workflows. When these components fail, the impact is felt across teams relying on shared assets and real-time collaboration.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you’re seeing similar Creative Cloud sync issues or have identified effective mitigations, community feedback can help accelerate understanding and resolution.

This finding underscores the critical role of background synchronization services, often invisible to users, in modern creative workflows. When these components fail, the impact is felt across teams relying on shared assets and real-time collaboration.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you’re seeing similar Creative Cloud sync issues or have identified effective mitigations, community feedback can help accelerate understanding and resolution.

Severity: Medium Impacted Organizations: 650+
Learn more

October 15, 2025 ID: CUA-2025-004

Based on guidance now provided by Microsoft, a fix for this issue is included in Microsoft Word build 16.0.19127.20314 or later, released as part of the Monthly Enterprise Channel (Version 2508).

Organizations should:

  • Identify endpoints running WINWORD.EXE build 16.0.19029.20244
  • Upgrade Microsoft Word to build 16.0.19127.20314 or later where possible
  • Validate that the updated build is fully deployed across affected devices
  • Monitor Word crash trends post-upgrade to confirm stability improvements

Microsoft release notes for this fix are available in the

Monthly Enterprise Channel documentation
.

This incident highlights the value of ControlUp’s global dataset and anomaly-detection capabilities, enabling early identification of widespread, high-impact issues before formal vendor documentation is broadly available.

If you observed Microsoft Word crashes or instability tied to build 16.0.19029.20244, confirming remediation after upgrading to 16.0.19127.20314 or later helps validate resolution at scale and improves collective response time across the community.

This incident highlights the value of ControlUp’s global dataset and anomaly-detection capabilities, enabling early identification of widespread, high-impact issues before formal vendor documentation is broadly available.

If you observed Microsoft Word crashes or instability tied to build 16.0.19029.20244, confirming remediation after upgrading to 16.0.19127.20314 or later helps validate resolution at scale and improves collective response time across the community.

This incident highlights the value of ControlUp’s global dataset and anomaly-detection capabilities, enabling early identification of widespread, high-impact issues before formal vendor documentation is broadly available.

If you observed Microsoft Word crashes or instability tied to build 16.0.19029.20244, confirming remediation after upgrading to 16.0.19127.20314 or later helps validate resolution at scale and improves collective response time across the community.

Severity: High Impacted Organizations: 500+
Learn more

October 12, 2025 ID: CUA-2025-005

Administrators running Microsoft Teams in VDI environments should:

  • Review crash logs for msteamsvdi.exe to confirm whether this signature is present
  • Identify the specific Teams client and VDI plugin versions deployed across affected environments
  • Monitor crash trends following Teams updates or platform changes
  • Apply Microsoft-recommended updates, mitigations, or hotfixes as they become available

Where possible, staggered rollouts and close post-update monitoring are advised to quickly detect improvements or regressions.

This finding highlights the importance of visibility into application behavior at scale—particularly for optimized components like Teams VDI that rely on tight integration between clients, plugins, and virtual environments.

ControlUp will continue tracking this crash signature globally and share updates as new insights emerge. If you’re experiencing Teams instability in VDI, we encourage you to share observations, correlations, or remediation steps with the community to help accelerate validation and resolution.

This finding highlights the importance of visibility into application behavior at scale—particularly for optimized components like Teams VDI that rely on tight integration between clients, plugins, and virtual environments.

ControlUp will continue tracking this crash signature globally and share updates as new insights emerge. If you’re experiencing Teams instability in VDI, we encourage you to share observations, correlations, or remediation steps with the community to help accelerate validation and resolution.

This finding highlights the importance of visibility into application behavior at scale—particularly for optimized components like Teams VDI that rely on tight integration between clients, plugins, and virtual environments.

ControlUp will continue tracking this crash signature globally and share updates as new insights emerge. If you’re experiencing Teams instability in VDI, we encourage you to share observations, correlations, or remediation steps with the community to help accelerate validation and resolution.

Severity: High Impacted Organizations: 250+
Learn more

September 24, 2025 ID: CUA-2025-006

Organizations using ManageEngine Endpoint Central should:

  • Review crash events related specifically to dcmetroapps.exe
  • Confirm the deployed agent version, particularly dcmetroapps.exe version 1.0.0.0
  • Check for known issues or updates provided by ManageEngine
  • Apply the latest available patches or agent updates as recommended

Given the low severity, monitoring for trend changes after updates is generally sufficient unless crash frequency increases.

This finding underscores the value of tracking background service stability, even when user-facing impact is limited. Small, recurring issues in management components can become more significant as environments scale.

ControlUp will continue monitoring this crash signature globally and share updates if the scope or severity changes. Community feedback on observed behavior or vendor guidance can help keep this finding current and actionable.

This finding underscores the value of tracking background service stability, even when user-facing impact is limited. Small, recurring issues in management components can become more significant as environments scale.

ControlUp will continue monitoring this crash signature globally and share updates if the scope or severity changes. Community feedback on observed behavior or vendor guidance can help keep this finding current and actionable.

This finding underscores the value of tracking background service stability, even when user-facing impact is limited. Small, recurring issues in management components can become more significant as environments scale.

ControlUp will continue monitoring this crash signature globally and share updates if the scope or severity changes. Community feedback on observed behavior or vendor guidance can help keep this finding current and actionable.

Severity: Low Impacted Organizations: 15+
Learn more

August 14, 2025 ID: CUA-2025-003

Based on observed behavior and Microsoft’s servicing model, organizations should:

  • Ensure the Intune Windows agent is allowed to auto-update across all managed endpoints
  • Verify that devices are running IME versions newer than 1.94, as older builds show the highest initial spike
  • Monitor crash trends after each IME update to validate stability improvements
  • Review correlations involving windowspackagemanager.dll, including version distribution across affected devices

Because the IME agent is continuously updated by Microsoft, manual rollback is typically not sustainable.
Ongoing monitoring is recommended to ensure newer agent versions reduce crash frequency as fixes are rolled out incrementally.

This finding highlights the operational risk of failures in foundational management agents that update silently and operate continuously in the background. Even when auto-updated, regressions can propagate quickly across large device populations.

ControlUp will continue tracking this crash pattern globally and share updates as new insights emerge. If you are observing IME instability tied to specific agent or module versions, sharing that data helps refine impact assessment and accelerate resolution.

This finding highlights the operational risk of failures in foundational management agents that update silently and operate continuously in the background. Even when auto-updated, regressions can propagate quickly across large device populations.

ControlUp will continue tracking this crash pattern globally and share updates as new insights emerge. If you are observing IME instability tied to specific agent or module versions, sharing that data helps refine impact assessment and accelerate resolution.

This finding highlights the operational risk of failures in foundational management agents that update silently and operate continuously in the background. Even when auto-updated, regressions can propagate quickly across large device populations.

ControlUp will continue tracking this crash pattern globally and share updates as new insights emerge. If you are observing IME instability tied to specific agent or module versions, sharing that data helps refine impact assessment and accelerate resolution.

Severity: Medium Impacted Organizations: 278+
Learn more

August 14, 2025 ID: CUA-2025-002

Organizations experiencing this issue should:

  • Upgrade Zoom from version 6.4.x to 6.5 or higher
  • Validate that the updated Zoom version is fully deployed across affected endpoints
  • Monitor crash trends post-upgrade to confirm stability improvements

ControlUp’s aggregated telemetry shows that upgrading to Zoom 6.5+ eliminates the crashing behavior entirely. At the time this pattern was identified, the resolution was not widely documented in Zoom release notes or broader IT community discussions.

This finding represents a high-confidence example of how targeted application updates can resolve widespread stability issues—even when vendor documentation is limited or delayed.

ControlUp will continue monitoring this crash signature globally. If you’ve observed similar Zoom and AMD Radeon interactions or can confirm improvements after upgrading, sharing that feedback helps accelerate validation for the wider community.

This finding represents a high-confidence example of how targeted application updates can resolve widespread stability issues—even when vendor documentation is limited or delayed.

ControlUp will continue monitoring this crash signature globally. If you’ve observed similar Zoom and AMD Radeon interactions or can confirm improvements after upgrading, sharing that feedback helps accelerate validation for the wider community.

This finding represents a high-confidence example of how targeted application updates can resolve widespread stability issues—even when vendor documentation is limited or delayed.

ControlUp will continue monitoring this crash signature globally. If you’ve observed similar Zoom and AMD Radeon interactions or can confirm improvements after upgrading, sharing that feedback helps accelerate validation for the wider community.

Severity: Medium Impacted Organizations: 100+
Learn more

July 16, 2025 ID: CUA-2025-001

Organizations using HP Poly Lens should:

  • Review crash logs related specifically to legacyhost.exe
  • Confirm whether affected endpoints are running legacyhost.exe version 2.1.0.425
  • Validate the deployed Poly Lens client version across the environment
  • Check for known issues related to pltsessionmanager.dll (v1.4.0.5)
  • Apply the latest HP Poly Lens updates, as newer versions show a notable reduction in crash frequency
  • Monitor conferencing stability closely following remediation or upgrades

Where feasible, staged rollouts and post-update monitoring are recommended to confirm improvements and prevent regressions.

This finding underscores how background services and device-management components can disproportionately affect end-user experience—especially for collaboration tools that depend on consistent audio and video performance.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you are experiencing similar conferencing issues related to Poly Lens or legacyhost.exe, sharing observations and mitigation outcomes with the ControlUp Community can help accelerate validation and resolution for all affected organizations.

This finding underscores how background services and device-management components can disproportionately affect end-user experience—especially for collaboration tools that depend on consistent audio and video performance.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you are experiencing similar conferencing issues related to Poly Lens or legacyhost.exe, sharing observations and mitigation outcomes with the ControlUp Community can help accelerate validation and resolution for all affected organizations.

This finding underscores how background services and device-management components can disproportionately affect end-user experience—especially for collaboration tools that depend on consistent audio and video performance.

ControlUp will continue monitoring this crash signature globally and share updates as new insights emerge. If you are experiencing similar conferencing issues related to Poly Lens or legacyhost.exe, sharing observations and mitigation outcomes with the ControlUp Community can help accelerate validation and resolution for all affected organizations.

Severity: High Impacted Organizations: 150+
Learn more