TEC-IT TBarCode ActiveX Control Remote File Creation Vulnerability

Vulnerability

A vulnerability exists in the TEC-IT TBarCode ActiveX control version 11.15, specifically in its licensing management via INI files. This flaw allows for remote file creation on the host system. Depending on the file's destination and name, this could lead to unauthorized code execution or file persistence within the context of the process running TBarCode.

Impact

Exploitation of this vulnerability could result in unauthorized file creation on the host system, with potential for executing malicious code or maintaining persistence through the created files.

Remediation

Users can update to TEC-IT TBarCode version 11.15.1, which addresses this vulnerability.

Added: Nov 12, 2025, 11:03 PM
Updated: Nov 12, 2025, 11:03 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.