PT-2026-5290 · Unknown · Barcodeocr
Daniel Bertoni
·
Published
2026-01-29
·
Updated
2026-01-29
·
CVE-2020-37016
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BarcodeOCR version 19.3.6
Description
BarcodeOCR 19.3.6 contains an unquoted service path issue that allows local attackers to execute code with elevated privileges during system startup. The unquoted path in the service configuration can be exploited to inject malicious executables that will run with LocalSystem privileges.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barcodeocr