Vulnerable Systems:
* GIGABYTE Dldrv2 ActiveX Control version 1.4.206.11
The vulnerability is the result of two items:
1) The unsafe method "dl()" allows automatically downloading and executing an arbitrary file.
2) Combined usage of the unsafe methods "SetDLInfo()" and "Bdl()" allows automatically downloading an arbitrary file to an arbitrary location on the user's system.
Workaround:
Set the kill-bit for the ActiveX control.