An ActiveX control is intended for use in a web browser, but it exposes dangerous methods that perform actions that are outside of the browser's security model (e.g. the zone or domain).
If you must expose a method, make sure to perform input validation on all arguments, and protect against all possible vulnerabilities.
Use code signing, although this does not protect against any weaknesses that are already in the control.
Where possible, avoid marking the control as safe for scripting.
Our security experts can help you identify and remediate CWE-618 vulnerabilities in your codebase.
Get Security Assessment