MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-5870
http://www.kb.cert.org/vuls/id/219470