An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary commands within the context of the application that uses the ActiveX control (typically Internet Explorer).
Vendor Status:
McAfee as issued an update for this vulnerablity.