CVE-2007-2644

Morovia Barcode ActiveX Pro 3.3.1304 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2644. PoCs published by shinnai.

AI-analyzed exploit summary This exploit leverages an arbitrary file overwrite vulnerability in Morovia Barcode ActiveX Professional 3.3 (build 1304) by abusing the Save method to overwrite the system.ini file, potentially causing system instability. The PoC is delivered via an HTML page with embedded VBScript and requires user interaction (clicking a button).

Description

A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/3899

This exploit leverages an arbitrary file overwrite vulnerability in Morovia Barcode ActiveX Professional 3.3 (build 1304) by abusing the Save method to overwrite the system.ini file, potentially causing system instability. The PoC is delivered via an HTML page with embedded VBScript and requires user interaction (clicking a button).

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Morovia Barcode ActiveX Professional 3.3 (build 1304)
No auth needed
Prerequisites: Victim must open the malicious HTML file in Internet Explorer · ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3899
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37786
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34248
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23934

Scores

EPSS 0.0469
EPSS Percentile 90.6%

Details

Status published
Products (1)
morovia/barcode_activex_control 3.3.1304
Published May 13, 2007
Tracked Since Feb 18, 2026