How can we address the issue of IIS application pool shutdowns after installing the Windows Server 2019 patch update (KB5035849),

ps-rizwan 21 Reputation points
2024-05-09T20:06:52.1+00:00

After installing the Windows Server 2019 patch update (KB5035849), customer encountered an issue with their IIS-hosted application. The associated application pool started experiencing shutdowns. Upon investigation, it was discovered that the Carbon Black antivirus software, responsible for monitoring the server was terminating the w3wp.exe process that hosts the web application.

As a temporary solution, the customer changed the configuration of the IIS application pool from "No Managed Code" with "Classic Managed Pipeline" mode to ".NET CLR Version v4.0.30319" with "Integrated Managed Pipeline" mode, which resolved the problem. However, the application vendor recommends using the "No Managed Code" with "Classic Managed Pipeline" mode.

It's important to note that this issue only occurs after installing the Windows Server 2019 patch update (KB5035849). We need help on how to address this issue while considering the application vendor's recommendation to have the IIS application pool running under "No Managed Code " with "Classic Managed Pipeline" setting.

When we roll back the Windows Patch update (KB5035849) we are not seeing issue.

When the Windows patch update (KB5035849) is installed, it causes the IIS process application pool, which is configured to run under "No Managed Code" with "Classic Managed Pipeline," to access files on the system drive. This access is flagged by Carbon Black as a potential vulnerability, leading to the termination of the application pool process w3wp.exe. How should we go about addressing this issue?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,507 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Wesley Li 5,330 Reputation points
    2024-05-15T07:49:54.3433333+00:00

    Hello

    The latest update for Server 2019 is "KB5036896", we may install the latest update then check the issue again as the KB5035849 got known issue related to "LSASS".

    Microsoft Update Catalog

    Since the process was killed by Carbon, we may ask for help from Carbon support why it would kill the process after the update.

    0 comments No comments