Vulnerability record · CVE-2011-3400 · published 14 December 2011
CVE-2011-3400: Windows OLE object handling flaw allows remote code execution
Microsoft · Windows Server 2003
Windows XP SP2/SP3 and Server 2003 SP2 mishandle OLE objects in memory, letting a crafted object embedded in a file corrupt memory and run attacker code. Because the flaw is in core OLE parsing, opening a malicious document is enough to trigger it, and the affected platforms are long past end of support.
Description
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication and a very high EPSS score, tempered only by the requirement for user interaction and the fact that the affected platforms are unsupported.
What it is
Windows XP SP2/SP3 and Server 2003 SP2 mishandle OLE objects in memory, letting a crafted object embedded in a file corrupt memory and run attacker code. Because the flaw is in core OLE parsing, opening a malicious document is enough to trigger it, and the affected platforms are long past end of support.
Impact
An attacker gains arbitrary code execution in the context of the user who opens the crafted file, which on these legacy systems is typically full administrative control of the host.
Attack surface
Reached remotely over the network via a crafted file containing a malicious OLE object; no authentication is required, but the victim must open or otherwise process the file (user interaction).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.71, 99th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply Microsoft security bulletin MS11-093, which addresses this OLE property vulnerability, to all remaining XP and Server 2003 systems.
- Where patching is impossible, retire or isolate the unsupported XP/Server 2003 hosts, since no further fixes will be issued.
- Block or strip OLE-embedded objects from untrusted documents at mail and web gateways.
- Restrict users from opening files from untrusted sources and enforce least privilege to limit the impact of code execution.
Detection
- Monitor for Office or OLE-capable applications spawning unexpected child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on document files written to or opened from temp, download or email attachment directories on XP/2003 hosts.
- Hunt for crash or memory-corruption events in OLE-related DLLs on legacy Windows systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3400 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3400), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.