CVE-2011-3402Active Exploitation(microsoft / windows_7)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft windows_7 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_7
  • windows_server_2003
  • windows_server_2008
  • windows_vista

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • False Positive: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-01)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
windows_7windows_server_2003windows_server_2008windows_vistawindows_xp

1 version affected across 5 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-29: 1Mentions · 2026-05-01: 3Active Exploitation · 2026-05-01: 3Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 203-2905-01
Signal classification2 categories
Active Exploitation
375.0%
False Positive
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-291
False Positive1
2026-05-013
Active Exploitation3
Full discourse4 posts
  • HSVSphere@HSVSphere
    False Positive

    Böyle bir şey yok, götünüzden uydurmayın. XNU hiç bir zaman font parsing yapmamıştır. Windows'daki mallığı hatırlıyorsunuz herhalde: https://www.cvedetails.com/cve/CVE-2011-3402 Bir de parsingi userspace'de yapmamak, kernel'da yapmak hiç bir şeyi hızlandırmayan güvenlik sorunudur. Berbat bir mimarinin belirtisidir. Ve Windows (NT harici berbatlar ötesi bir sistem) bile bunu artık yapmıyor. Darwin'deki ATS, CoreText, vb. gibi hepsi userspace. Ve, yeni emoji için font dosya parser'ı güncelleme gerektirmez (yeni unicode format kuralları gelmemişse). Rendering için sadece yeni font dosyası yeterlidir (selection, yani grapheme cluster algoritmaları vb atladım, onun için başka bir komponent güncelleme gerektirir) Not: Kernel seviyesindeki bitmap ascii fontlar dahil değildir, ve bunlar bile artık eskide kalıyor (bkz: Linux CONFIG_VT=n)

    Post summary

    The author argues that XNU never parses fonts, refuting the presence of CVE-2011-3402 in the OS. No proof, exploit, or patch information is provided.

    00050223
    18.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2011-3402 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-10-06, establishing a remediation due date of 2025-10-27 for covered entities CISA KEV. The entry tracks a Windows kernel remote code execution vulnerability in the TrueType…

    Post summary

    CISA cataloged CVE-2011-3402 as a known exploited Windows kernel RCE, setting a remediation deadline, which confirms active exploitation.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2011-3402: CISA adds CVE-2011-3402 to KEV: Windows win32k.sys TrueType font parsing RCE via crafted fonts in Word docs or web pages; patch or mitigate now.

    Post summary

    The post announces that CVE-2011-3402, a Windows win32k.sys TrueType font parsing RCE, has been added to the CISA KEV list and urges immediate patching or mitigation.

    1000032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2011-3402-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet points to a research page claiming that CVE‑2011‑3402 is being actively exploited in Windows environments, but it offers no additional technical or mitigation details.

    0000029
    152 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_7--x64
OSmicrosoftwindows_7--x86
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_vista---
OSmicrosoftwindows_xp---
OSmicrosoftwindows_xp---

Explore more