Junglewise Threat Intelligence

CVE-2011-3402: Microsoft Windows remote code execution in TrueType font parsing engine

CVE-2011-3402 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-10-06

Technologies: Microsoft Windows Vista, Microsoft Windows, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Windows 7, Microsoft Windows XP. Vendors: Microsoft.

Executive brief

A vulnerability exists in how older versions of Microsoft Windows process TrueType fonts. An attacker can exploit this by tricking a user into opening a malicious Word document or visiting a compromised website, potentially allowing the attacker to take full control of the computer. This flaw was notably used in the wild by the Duqu malware to target industrial and government systems.

Technical details

The vulnerability resides within the TrueType font parsing engine in the kernel-mode driver win32k.sys. It is triggered when the system processes specially crafted font data embedded in documents (such as Microsoft Word) or delivered via web pages. Because the parsing occurs in kernel mode, successful exploitation allows an attacker to execute arbitrary code with elevated privileges. This is a remote attack vector that requires user interaction (opening a file or visiting a site). Microsoft has released security bulletins (MS11-087, MS12-034) to address this issue.

Affected products

  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2, R2 SP1
  • Microsoft Windows 7 Gold, SP1

Timeline

  • 2011-11-03: disclosed: Initial Microsoft security advisory released
  • 2011-11-01: exploited: Exploited in the wild by Duqu malware
  • 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats