A set of technologies in .NET for building web applications and web services. Miscellaneous topics that do not fit into specific categories.
Hi there!
This morning there was a Defender update, I have installed it an now it works!!!
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Recently my local hosted IIS services is not running after the new update. My visual studio projects also can't be run as well. I have to delete the new update in order to run my projects and local hosted services again. May I know what is the problem?
A set of technologies in .NET for building web applications and web services. Miscellaneous topics that do not fit into specific categories.
Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Hi there!
This morning there was a Defender update, I have installed it an now it works!!!
It seems the issue is not limited to IIS.
We have a WCF service self-hosted with ServiceHost (.NET Framework), and after installing the October 2025 cumulative update, the service stopped working.
Clients now get this exception:
System.ServiceModel.CommunicationException: An error occurred while receiving the HTTP response to http(s)://<host>:<port>/ServicePath This could be due to the service endpoint binding not using the HTTP protocol. This could also be due to an HTTP request context being aborted by the server (possibly due to the service shutting down). See server logs for more details.
Changing the binding from BasicHttpBinding or BasicHttpsBinding to NetTcpBinding makes the service work again without uninstalling the update.
It looks like the update changed how HTTP.sys handles self-hosted HTTP/HTTPS endpoints (possibly related to CVE-2025-55248).
Could Microsoft confirm if this change is intentional or if it’s an unexpected issue breaking WCF SelfHost applications?
Do you plan to release a fix or provide an official workaround for affected systems?
Not just an IIS problem. It's breaking our app on some subset of customer machines (and, luckily, mine). Minimal repro:
using System;
using System.Net;
using System.Net.Http;
using System.Threading;
using System.Threading.Tasks;
class MinimalRepro
{
static async Task Main()
{
var listener = new HttpListener();
listener.Prefixes.Add("http://localhost:8089/");
listener.Start();
listener.BeginGetContext(ar =>
{
try
{
var context = listener.EndGetContext(ar); // FAILS HERE
context.Response.StatusCode = 200;
context.Response.Close();
}
}, null);
await Task.Delay(200);
// Trigger the error
using var client = new HttpClient();
await client.GetAsync("http://localhost:8089/");
listener.Stop();
}
}
ERROR: 50 - The request is not supported.
Unhandled exception. System.Net.Http.HttpRequestException: An error occurred while sending the request.
---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host..
---> System.Net.Sockets.SocketException (10054): An existing connection was forcibly closed by the remote host.
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.CreateException(SocketError error, Boolean forAsyncThrow)
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ReceiveAsync(Socket socket, CancellationToken cancellationToken)
at System.Net.Sockets.Socket.ReceiveAsync(Memory`1 buffer, SocketFlags socketFlags, Boolean fromNetworkStream, CancellationToken cancellationToken)
As someone pointed out, the problem is not just IIS, but anything opening a port using .net HTTPListener. Minimal reproduction : https://github.com/BloomBooks/httplistener-test
Uninstalled KB5066835 AND KB5065789 and back to normal.
I feel the guy with the 500 computers...
And MS Devs, how is it possible to deploy a Windows Update you BUILT with Visual Studio and not see VS is not working after you deploy on your test servers? Wow...