LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2011-3402: Microsoft Windows Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 6, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2011-3402 to its Known Exploited Vulnerabilities catalog on Oct 6, 2025, with a federal patch deadline of Oct 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via…

CVE-2011-3402 is a remote code execution vulnerability in Microsoft Windows that stems from a flaw in the TrueType font parsing engine inside the kernel-mode driver win32k.sys. An attacker can trigger it by supplying crafted font data embedded in a Word document or a web page, potentially allowing arbitrary code to run with elevated privileges on the target system. Because the issue lives in a core kernel component used for font handling, it can affect a wide range of Windows installations that process untrusted documents or web content, making timely identification and remediation important for IT and security teams.

Public detail is limited to the description above; exact affected builds, severity metrics, and full technical root cause must be confirmed against the Microsoft security advisory for this CVE.

How it works

The vulnerability resides in the TrueType font parsing logic within win32k.sys, a kernel-mode driver that handles graphics and windowing functions on Windows. When the system processes font data—whether loaded from a document or rendered by a browser—the parser fails to handle certain malformed TrueType structures safely. An attacker who can deliver a specially crafted font (for example, embedded inside a Word file opened by a user or served from a web page) can cause the kernel component to execute attacker-controlled code.

Because the flaw is in kernel-mode code, successful exploitation typically yields high-privilege execution on the local system. No specific CWE identifier is provided in the available record, so the weakness is best treated as an unspecified memory-safety or parsing error in a privileged font engine. Exact exploit mechanics, required user interaction levels, and any sandbox bypass details are not supplied here and should be verified from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the win32k.sys TrueType font parsing engine—essentially any supported Windows installation that can open Word documents or render web pages containing fonts. Typical locations include endpoint workstations, terminal servers, and any host that processes Office files or browses the internet under a user context.

Confirm exact version ranges and detection methods with the official Microsoft advisory before declaring systems clean or affected.

How to remediate

The primary remediation is to apply the security update Microsoft released for this vulnerability. Follow the vendor’s installation instructions, reboot if required, and verify the patch is present via Windows Update history or compliance tooling.

Hardening steps that reduce the attack surface for this class of font-parsing issues include restricting the ability of Office and browsers to load untrusted fonts, enabling Protected View or Application Guard for Office documents, and keeping the entire Windows security update stack current.

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls that limit delivery of crafted font data and contain potential compromise:

These measures reduce risk but do not eliminate it; schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full system compromise and subsequent data theft. If you suspect exploitation of CVE-2011-3402, treat the host as potentially breached: isolate it, collect forensic images, rotate credentials, and review access logs for lateral movement. Known ransomware use of this specific CVE is not documented in the available record. As a quick check for whether associated email addresses appear in known breach corpora, you can run a free exposure scan of your email addresses against public breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVOct 6, 2025
Federal patch deadlineOct 27, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities