MS15-034 | Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)
Phil Lello
phil at dunlop-lello.uk
Thu Apr 16 10:18:24 EDT 2015
Hi all,
Would anyone consider
https://technet.microsoft.com/library/security/MS15-034 a risk for Windows
hosted Shibboleth IdP or SP instances, or indeed Shibboleth SPs that trust
an ADFS3 IdP?
I'm not aware of this issue affecting any SP or IdP configurations I have
an interest in, as I suppose the primary risk is to systems hosting
Shibboleth SP or IdP on Windows, of course if a trusted endpoint (such as
ADFS3 which uses HTTP.SYS) is compromised then the overall system security
suffers.
Best wishes,
Phil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150416/aa9823a9/attachment.html
More information about the users
mailing list