Vulnerable Systems:
* GIGABYTE Dldrv2 ActiveX Control version 1.4.206.11
The vulnerability is caused by missing input validation of the "item" argument passed to the "SetDLInfo()" method and can be exploited via array-indexing errors to corrupt memory.
Successful exploitation allows execution of arbitrary code.
Workaround:
Set the kill-bit for the ActiveX control.