CVE-2016-3227
9.8
CRITICAL · CVSS 3.0 · EPSS 25.5% (pctl 98)
Patch early
EPSS 25.5% — above the 10% action threshold.
Description
Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 25.46% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-06-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | windows server 2012 |
References
→ the Explorer · watch your stack · NVD