CVE-2011-3400 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 71.4% (pctl 99)
Patch early
A public exploit exists.
Description
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 71.37% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-12-14 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows server 2003 |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows - OLE Object File Handling Remote Code Execution (Metasploit) | 2012-06-06 |
References
- http://www.us-cert.gov/cas/techalerts/TA11-347A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-093
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14668
- http://www.us-cert.gov/cas/techalerts/TA11-347A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-093
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14668
→ the Explorer · watch your stack · NVD