CVE-2011-3402
microsoft windows 7, microsoft windows server 2003, microsoft windows server 2008
Published 4 Nov 2011 · updated 16 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 6 Oct 2025, with a remediation deadline of 27 Oct 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
References
- blogs.mcafee.com/mcafee-labs/the-day-of-the-golden-jackal-%E2%80%93-further-tales-of-the-stuxnet-files · Broken Link
- blogs.technet.com/b/msrc/archive/2011/11/03/microsoft-releases-security-advisory-2639658.aspx · Vendor Advisory
- isc.sans.edu/diary/Duqu+Mitigation/11950 · Third Party Advisory
- secunia.com/advisories/49121 · Vendor Advisory
- secunia.com/advisories/49122 · Vendor Advisory
- technet.microsoft.com/security/advisory/2639658 · Vendor Advisory
- www.securelist.com/en/blog/208193197/The_Mystery_of_Duqu_Part_Two · Not Applicable
- www.securitytracker.com/id?1027039 · Broken Link
- www.symantec.com/connect/w32-duqu_status-updates_installer-zero-day-exploit · Not Applicable
- www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf · Not Applicable
- www.us-cert.gov/cas/techalerts/TA11-347A.html · US Government Resource
- www.us-cert.gov/cas/techalerts/TA12-129A.html · US Government Resource
- www.us-cert.gov/cas/techalerts/TA12-164A.html · US Government Resource
- www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-291-01E.pdf · US Government Resource
- docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-087 · Vendor Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-034 · Vendor Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-039 · Vendor Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13998 · Broken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15290 · Broken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15645 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-3402 · US Government Resource