MW6 Technologies Barcode ActiveX Control Memory Corruption

Strike ID:
E09-38a01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
2
Year:
2009

Description

This strike exploits a vulnerability in MW6 Technologies ActiveX Control barcode.dll. Specifically the vuln is due to the way in which the Supplement property of this control is handled. If this property is assigned a value of greater than 0x90 and less than 0xCF8, the code will overwrite a pointer resulting in memory corruption.

CVE

Bid