CVE-2011-3402CISA KEV
Microsoft Windows Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.
- Product
- Windows
- Added to KEV
- 6 Oct 2025
- Federal remediation due
- 27 Oct 2025
- Known ransomware use
- Not reported