Vulnerability Name: | CVE-2016-3227 (CCN-113670) | ||||||||||||
Assigned: | 2016-06-14 | ||||||||||||
Published: | 2016-06-14 | ||||||||||||
Updated: | 2019-05-08 | ||||||||||||
Summary: | Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability." CWE-416: Use After Free | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-3227 Source: CCN Type: Microsoft Security Bulletin MS16-071 Security Update for Microsoft Windows DNS Server (3164065) Source: SECTRACK Type: UNKNOWN 1036095 Source: MS Type: UNKNOWN MS16-071 Source: XF Type: UNKNOWN ms-dns-cve20163227-code-exec(113670) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |