CVE-2011-3402 is an unspecified vulnerability in the TrueType font parsing engine (win32k.sys) affecting multiple versions of Microsoft Windows, including XP, Server 2003, Vista, Server 2008, and Windows 7. This high-severity vulnerability (CVSS 8.8) allows remote attackers to execute arbitrary code by tricking users into opening crafted font data within Word documents or web pages, requiring user interaction but with low attack complexity. It has a critical FAUCET Risk Score of 100/100 and an extremely high EPSS score, indicating a significant threat. Notably, this vulnerability was actively exploited in the wild by the Duqu malware in November 2011 and is listed in CISA's KEV catalog, with community discussion and media coverage reflecting its historical impact. While Metasploit includes a post-exploitation module for Duqu, public exploit code on platforms like ExploitDB and Nuclei is not readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.