CVE-2016-0037: Microsoft Windows Server 2012

High severity, CVSS 7.5. EPSS: 25.7% chance of exploitation in the next 30 days.

The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."

Affected products

  • Microsoft Windows Server 2012: version r2 only

Published 2016-02-10. Last modified 2026-06-17.