MS15-034 | Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)

Cantor, Scott cantor.2 at osu.edu
Thu Apr 16 13:12:07 EDT 2015


On 4/16/15, 10:18 AM, "Phil Lello" <phil at dunlop-lello.uk> wrote:
>
>Would anyone consider 
>https://technet.microsoft.com/library/security/MS15-034 a risk for Windows hosted Shibboleth IdP or SP instances, or indeed Shibboleth SPs that trust an ADFS3 IdP?

The same as with any web server vulnerability. I'm not sure what would make this one different, but I haven't looked closely to be fair.

>I'm not aware of this issue affecting any SP or IdP configurations I have an interest in, as I suppose the primary risk is to systems hosting Shibboleth SP or IdP on Windows, of course if a trusted endpoint (such as ADFS3 which uses HTTP.SYS) is compromised then the overall system security suffers.

Inquiring into the patching practices of federated partners is one of those things that you probably don't want to do unless you're prepared for the answer. For example, say they were awful (hint, hint)...what would you do as a result? Whose functionality are you prepared to turn off and who's going to defend that decision to management?

Just doesn't happen much, sad to say.

-- Scott



More information about the users mailing list