vendor:
BarCodeWiz Barcode ActiveX Control
by:
loneferret
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: BarCodeWiz Barcode ActiveX Control
Affected Version From: BarCodeWiz Barcode ActiveX Control 3.29
Affected Version To: BarCodeWiz Barcode ActiveX Control 3.29
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP3 with Internet Explorer 6
2010
BarCodeWiz Barcode ActiveX Control 3.29 BoF (SEH)
This exploit is a buffer overflow vulnerability found in BarCodeWiz Barcode ActiveX Control 3.29. It is triggered when the LoadProperties method is called. The vulnerability allows an attacker to execute arbitrary code on the target system.
Mitigation:
Update the BarCodeWiz Barcode ActiveX Control to a non-vulnerable version. Alternatively, disable or remove the ActiveX control from the system.