Toad for Oracle itself does not contain these vulnerabilities. So, if the users in the organization do not use SQL Tracker at all and still want to use an earlier version of Toad for Oracle than v13.1.1, you can simply delete the SQL Tracker folder from within Toad for Oracle's installation folder and that version of Toad will no longer have that potential vulnerability. Please note that if the user has any other versions of Toad for Oracle installed, this would need to be done to each version of Toad installed on the user's machine.
Simply not using SQL Tracker would also not open up the potential vulnerability as well, but it would be best to completely remove the SQL Tracker folder, mentioned above, to make absolutely sure that no one can exploit the vulnerability.
Also, note that this won't remove the potential vulnerability if it exists from any other applications on the user's machine. If there are other applications (non-Quest) installed that use Microsoft Visual C++ 2010 (or earlier) runtimes, you will need to address those separately with that software's vendor.