<div dir="ltr"><div><div><div><div>Hi all,<br><br></div>Would anyone consider <a href="https://technet.microsoft.com/library/security/MS15-034">https://technet.microsoft.com/library/security/MS15-034</a> a risk for Windows hosted Shibboleth IdP or SP instances, or indeed Shibboleth SPs that trust an ADFS3 IdP?<br><br></div>I&#39;m not aware of this issue affecting any SP or IdP configurations I have an interest in, as I suppose the primary risk is to systems hosting Shibboleth SP or IdP on Windows, of course if a trusted endpoint (such as ADFS3 which uses HTTP.SYS) is compromised then the overall system security suffers.<br><br></div>Best wishes,<br><br></div>Phil<br></div>