Oracle Siebel Option Pack for IE ActiveX control contains a vulnerability when initializing memory used by the "NewBusObj" method. By browsing to a website hosting malicious content or opening a crafted HTML document (e.g. e-mail message or attachment), an attacker could instantiate the vulnerable ActiveX control and corrupt system memory in such a way that could be leveraged to execute arbitrary code.
Oracle Siebel Option Pack for IE
BeyondTrust Prevention and Detection:
BeyondTrust's Blink® Professional Edition protects from this vulnerability.
BeyondTrust's Retina® Network Security Scanner scans devices to detect for this vulnerability.
Retina Audit 13416 - Oracle Siebel Option Pack ActiveX Control Code Execution (Zero-Day)
Apply appropriate vendor patches.