{
    "id": "CVE-2016-3227",
    "published": "2016-06-16 01:59:29",
    "last_modified": "2026-06-17 00:45:19",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": null,
    "description": "Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka \"Windows DNS Server Use After Free Vulnerability.\"",
    "epss_score": "0.25462",
    "epss_percentile": "0.97896",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:16",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 25.5% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "windows_server_2012"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.securitytracker.com/id/1036095",
        "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-071",
        "http://www.securitytracker.com/id/1036095",
        "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-071"
    ]
}