CVE-2011-3402
HIGH KEV RANSOMWAREMicrosoft Windows - RCE
Title source: llmDescription
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
References (21)
... and 1 more
Scores
CVSS v3
8.8
EPSS
0.8831
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-10-06
VulnCheck KEV
2011-11-04
InTheWild.io
2020-09-28
ENISA EUVD
EUVD-2011-3365
Ransomware Use
Confirmed
Status
published
Products (5)
microsoft/windows_7
(4 CPE variants)
microsoft/windows_server_2003
(2 CPE variants)
microsoft/windows_server_2008
(5 CPE variants)
microsoft/windows_vista
(2 CPE variants)
microsoft/windows_xp
(4 CPE variants)
Published
Nov 04, 2011
KEV Added
Oct 06, 2025
Tracked Since
Feb 18, 2026