Mitsubishi MC-WorkX Suite Insecure ActiveX Control (IcoLaunch)

This proof of concept will launch an arbritrary executable when the Login Client button is clicked. An attacker could use this to have the victim launch malicious code from a remote share. Calc is used in this example.