MS15-034 | Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)

Phil Lello phil at dunlop-lello.uk
Thu Apr 16 10:18:24 EDT 2015


Hi all,

Would anyone consider
https://technet.microsoft.com/library/security/MS15-034 a risk for Windows
hosted Shibboleth IdP or SP instances, or indeed Shibboleth SPs that trust
an ADFS3 IdP?

I'm not aware of this issue affecting any SP or IdP configurations I have
an interest in, as I suppose the primary risk is to systems hosting
Shibboleth SP or IdP on Windows, of course if a trusted endpoint (such as
ADFS3 which uses HTTP.SYS) is compromised then the overall system security
suffers.

Best wishes,

Phil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150416/aa9823a9/attachment.html 


More information about the users mailing list