CVE-2016-3227
CRITICALWindows Server 2012 - Remote Code Execution via DNS Server Use-After-Free
Title source: llmDescription
Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036095
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-071
Scores
CVSS v3
9.8
EPSS
0.2546
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
microsoft/windows_server_2012
microsoft/windows_server_2012
r2 (3 CPE variants)
Published
Jun 16, 2016
Tracked Since
Feb 18, 2026