CVE-2016-3227

CRITICAL

Windows Server 2012 - Remote Code Execution via DNS Server Use-After-Free

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036095

Scores

CVSS v3 9.8
EPSS 0.2546
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
microsoft/windows_server_2012
microsoft/windows_server_2012 r2 (3 CPE variants)
Published Jun 16, 2016
Tracked Since Feb 18, 2026