DirectX Files Viewer xweb.ocx (2,0,16,15 and older)
A vulnerability was reported in the Microsoft DirectX Files Viewer (xweb.ocx) ActiveX control. A remote user may be able to cause the viewer to execute arbitrary code with the privileges of the target user.
While it was not specified which ones, according to the report, the latest IE/OS patches will correct this flaw. Windows 2000 SP3 and Windows XP SP1 are expected to include a fix.