peter bassill · operator
$ cve CVE-2016-3227 JSON

CVE-2016-3227

9.8
CRITICAL · CVSS 3.0 · EPSS 25.5% (pctl 98)

Patch early

EPSS 25.5% — above the 10% action threshold.

Description

Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS25.46% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploitnone known
Published2016-06-16
Last modified2026-06-17

Affected (1)

VendorProduct
microsoftwindows server 2012

References

→ the Explorer  ·  watch your stack  ·  NVD