vendor:
BarCodeWiz ActiveX Control
by:
Parveen Vashishtha
N/A
CVSS
HIGH
Stack Overflow
CWE
Product Name: BarCodeWiz ActiveX Control
Affected Version From: 2.52
Affected Version To: 2.52
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000
2007
BarCodeWiz ActiveX Control 2.52 (BarcodeWiz.dll) Stack Overflow SEH Overwrite Exploit
This exploit takes advantage of a stack overflow vulnerability in the BarCodeWiz ActiveX Control 2.52 (BarcodeWiz.dll). By exploiting this vulnerability, an attacker can overwrite the Structured Exception Handling (SEH) chain, potentially allowing for arbitrary code execution. This exploit includes a shellcode that opens the Windows Calculator application on Windows 2000.
Mitigation:
Update to a patched version of the BarCodeWiz ActiveX Control or remove the control from the system.