Back

CVE-2016-3227

CRITICAL

Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."

Published: Jun 16, 2016 Modified: Jun 17, 2026

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
microsoft windows_server_2012 -
microsoft windows_server_2012 r2
microsoft windows_server_2012 r2
microsoft windows_server_2012 r2

GitHub Security Advisory GHSA-wpxq-2qxf-q435

Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 25.46%

Top 2% most likely to be exploited

Threat Score 46.8 / 100

Data Sources

NVD EPSS GitHub