CORRUPT_ACCESS_TOKEN

Code: 0x28 (40)

As HRESULT:As NTSTATUS:

Description

The CORRUPT_ACCESS_TOKEN bug check has a value of 0x00000028.

This bug check appears very infrequently.

Important

This article is for programmers. If you're a customer who has received a blue screen error code while using your computer, see Troubleshoot blue screen errors.

Resolution

The !analyze debug extension displays information about the bug check and can be helpful in determining the root cause.

Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.

Associated Modules

ModuleCodeFound inDescription
EhStorAuthn.exe0x287Invalid data error
EventCreate.exe0x2878.11011%1
VSSVC.exe0x281011Volume Shadow Copy Service error: The Microsoft Software Shadow Copy Provider (SWPRV) service is disabled. Enable the service and try again. %1
cipher.exe0x2878.11011Your .CER file was created successfully.
compact.exe0x281011Cannot query system's Compact state:
dsreg.dll0x281011The parameter value should not be NULL or empty. Function: %1; Parameter: %2.
dssec.dll0x2878.11011Receive computer journal
ehepgres.dll0x287%1
hvloader.dll0x2811Hypervisor launch failed; the hypervisor image is revision %1, but the currently installed virtualization software only supports launching revision %2 hypervisor images.
hvservice.sys0x2810Hypervisor launch failed; the hypervisor image is revision %1, but the currently installed virtualization software only supports launching revision %2 hypervisor images.
nslookup.exe0x2878.11011*** Can't find server address for '%1':
powershell.exe0x2811PowerShell 2.0 has been deprecated. Using default PowerShell instead.
reagentc.exe0x288.11011%1: The index of the recovery image (WIM) file must be specified.
sc.exe0x2878.11011LockOwner : %1 LockDuration : %2 (seconds since acquired)
w32time.dll0x281011The time provider '%1' was stopped with error %2.
webservices.dll0x2878.11011The specified decimal value was not valid.
wecutil.exe0x2878.11011Windows Event Collector Utility Enables you to create and manage subscriptions to events forwarded from remote event sources that support WS-Management protocol. Usage: You can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format) version of the command and option names. Commands, options and option values are case-insensitive. (ALL UPPER-CASE = VARIABLE) wecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...] Commands: es (enum-subscription) List existent subscriptions. gs (get-subscription) Get subscription configuration. gr (get-subscriptionruntimestatus) Get subscription runtime status. ss (set-subscription) Set subscription configuration. cs (create-subscription) Create new subscription. ds (delete-subscription) Delete subscription. rs (retry-subscription) Retry subscription. qc (quick-config) Configure Windows Event Collector service. Common options: /h|? (help) Get general help for the wecutil program. wecutil { -help | -h | -? } For arguments and options, see usage of specific commands: wecutil COMMAND -?
wevtsvc.dll0x281011The event logging service encountered an error when attempting to apply one or more policy settings.
wevtutil.exe0x2878.11011List the names of all logs. Usage: wevtutil { el | enum-logs } Example: The following example lists the names of all logs. wevtutil el
whealogr.dll0x2871011A fatal hardware error has occurred. Component: %5 Error Source: %1 The details view of this entry contains further information.
win32k.sys0x2878.1WindowText
win32kbase.sys0x281011WindowText
22 entries