CVE-2016-0044Improper Input Validation in Microsoft Windows Server 2012

Severity
7.5HIGHNVD
EPSS
31.7%
top 3.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateMay 14

Description

Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loading Denial of Service Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jwpw-2pjx-j868: Sync Framework in Microsoft Windows 82022-05-14

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - February 20162016-02-09
Talos
Microsoft Patch Tuesday - February 20162016-02-09