Vulnerability Description
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 7 | - |
| Microsoft | Windows Server 2003 | - |
| Microsoft | Windows Server 2008 | - |
| Microsoft | Windows Vista | - |
| Microsoft | Windows Xp | - |
References
- http://blogs.mcafee.com/mcafee-labs/the-day-of-the-golden-jackal-%E2%80%93-furthBroken Link
- http://blogs.technet.com/b/msrc/archive/2011/11/03/microsoft-releases-security-aVendor Advisory
- http://isc.sans.edu/diary/Duqu+Mitigation/11950Third Party Advisory
- http://secunia.com/advisories/49121Vendor Advisory
- http://secunia.com/advisories/49122Vendor Advisory
- http://technet.microsoft.com/security/advisory/2639658Vendor Advisory
- http://www.securelist.com/en/blog/208193197/The_Mystery_of_Duqu_Part_TwoNot Applicable
- http://www.securitytracker.com/id?1027039Broken Link
- http://www.symantec.com/connect/w32-duqu_status-updates_installer-zero-day-exploNot Applicable
- http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepaNot Applicable
- http://www.us-cert.gov/cas/techalerts/TA11-347A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-129A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-164A.htmlUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-291-01E.pdfUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-08Vendor Advisory
FAQ
What is CVE-2011-3402?
CVE-2011-3402 is a vulnerability with a CVSS score of 8.8 (HIGH). Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2...
How severe is CVE-2011-3402?
CVE-2011-3402 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-3402?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 7, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows Xp.