Vulnerabilities > CVE-2007-3435 - Buffer Overflow vulnerability in RKD Software Barcode Activex 4.9

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
rkd-software
critical
exploit available
metasploit

Summary

Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.

Vulnerable Configurations

Part Description Count
Application
Rkd_Software
1

Exploit-Db

  • descriptionRKD Software BarCodeAx.dll v4.9 ActiveX Remote Stack Buffer Overflow. CVE-2007-3435. Remote exploit for windows platform
    idEDB-ID:16565
    last seen2016-02-02
    modified2010-05-09
    published2010-05-09
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16565/
    titleRKD Software BarCodeAx.dll 4.9 - ActiveX Remote Stack Buffer Overflow
  • descriptionBarCode ActiveX Control BarCodeAx.dll 4.9 Remote Overflow Exploit. CVE-2007-3435. Remote exploit for windows platform
    fileexploits/windows/remote/4094.html
    idEDB-ID:4094
    last seen2016-01-31
    modified2007-06-22
    platformwindows
    port
    published2007-06-22
    reportercallAX
    sourcehttps://www.exploit-db.com/download/4094/
    titleBarCode ActiveX Control BarCodeAx.dll 4.9 - Remote Overflow Exploit
    typeremote

Metasploit

descriptionThis module exploits a stack buffer overflow in RKD Software Barcode Application ActiveX Control 'BarCodeAx.dll'. By sending an overly long string to the BeginPrint method of BarCodeAx.dll v4.9, an attacker may be able to execute arbitrary code.
idMSF:EXPLOIT/WINDOWS/BROWSER/BARCODE_AX49
last seen2020-06-14
modified2017-11-08
published2010-02-12
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3435
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/barcode_ax49.rb
titleRKD Software BarCodeAx.dll v4.9 ActiveX Remote Stack Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/86297/barcode_ax49.rb.txt
idPACKETSTORM:86297
last seen2016-12-05
published2010-02-15
reporterpatrick
sourcehttps://packetstormsecurity.com/files/86297/RKD-Software-BarCodeAx.dll-v4.9-ActiveX-Remote-Stack-Buffer-Overflow.html
titleRKD Software BarCodeAx.dll v4.9 ActiveX Remote Stack Buffer Overflow