An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buffer. The attacker may then remotely execute arbitrary code.
https://www.cisa.gov/news-events/ics-advisories/icsa-14-079-03
http://www.securityfocus.com/bid/66740
http://www.securityfocus.com/bid/66732