CVE-2011-3402CISA KEVEPSS p99.5%

CVE-2011-3402Microsoft Windows Remote Code Execution Vulnerability

Microsoft / Windows

Description

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.

Scoring

EPSS78.29% probability of exploitation · percentile 99.5% · 2026-06-19T12:03:05Z

CISA KEV entry

Added to KEV: 2025-10-06

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Windows Remote Code Execution Vulnerabilitykev-cve-2011-34020%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
CVE
Microsoft Word Remote Code Execution Vulnerability
CVE
Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
CVE
CVE-2026-33114
CVE
CVE-2026-40364
CVE
Microsoft Office Stack-based Buffer Overflow Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.