PT-2025-46731 · Tec It · Tbarcode

Published

2025-11-12

·

Updated

2025-11-13

·

CVE-2022-4983

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TEC-IT TBarCode version 11.15
Description The TBarCode11.ocx ActiveX/OCX control in version 11.15 has a flaw in its licensing handling, which relies on INI-files. This can be exploited to remotely create files on the host filesystem. Depending on the allowed filenames and file creation locations, attackers may be able to write files that lead to code execution or persistence with the privileges of the hosting process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-4983

Affected Products

Tbarcode