EIP-2026-118305

PRE-CVE

Barcodewiz 'Barcodewiz.dll' ActiveX Control - 'Barcode' Method Remote Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118305. PoCs published by coolkaveh.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the BarCodeWiz ActiveX control by supplying an overly long string to the 'Barcode' property. Successful exploitation can lead to arbitrary code execution in the context of the application using the ActiveX control, typically Internet Explorer.

Description

Barcodewiz 'Barcodewiz.dll' ActiveX Control - 'Barcode' Method Remote Buffer Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by coolkaveh · htmlremotewindows
https://www.exploit-db.com/exploits/37542

This exploit targets a buffer overflow vulnerability in the BarCodeWiz ActiveX control by supplying an overly long string to the 'Barcode' property. Successful exploitation can lead to arbitrary code execution in the context of the application using the ActiveX control, typically Internet Explorer.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: BarCodeWiz ActiveX Control 4.0.0.0
No auth needed
Prerequisites: Victim must open a malicious webpage or HTML email · BarCodeWiz ActiveX control must be installed and registered
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026