Insecure DLL loading in Windows and Windows Server - CVE-2016-0044
Published: February 9, 2016 / Updated: April 7, 2020
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists when Microsoft Sync Framework processes specially crafted input that uses the “change batch” structure. A remote authenticated user can send specially crafted traffic to the SyncShareSvc service and cause it to stop responding.