Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted page or file.
Successful exploit attempts allow an attacker to execute arbitrary code within the context of the application that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Vendor Status:
Currently, we are not aware of any vendor-supplied patches.