Oval Definition:oval:org.cisecurity:def:871
Revision Date:2016-07-29Version:33
Title:Windows DNS Server Use After Free Vulnerability - CVE-2016-3227 (MS16-071)
Description:Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2016-3227
Platform(s):Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s):
Definition Synopsis
  • Microsoft Windows Server 2012 + file version
  • Microsoft Windows Server 2012 (64-bit) is installed
  • AND Check if dns.exe version is less than 6.2.9200.21872
  • OR Microsoft Windows Server 2012 R2 + file version
  • Microsoft Windows Server 2012 R2 is installed
  • AND Check if dns.exe version is less than 6.3.9600.18340
  • BACK