Security scans (e.g., Nessus) identify the Provisioning Server and Identity Manager servers as vulnerable to MS08-070: Vulnerabilities in Visual Basic 6.0 ActiveX Controls Could Allow Remote Code Execution (KB 932349). The scan specifically flags the following file:
C:\Windows\SysWOW64\msflxgrd.ocx
The vulnerability report refers specifically to msflxgrd.ocx.
c:\windows\syswow64\msflxgrd.ocx
To mitigate this vulnerability, consider one of the following options based on your operational requirements. Note that removing or altering files may impact the functionality of the Provisioning Manager interface.
If you must keep the component installed but need to address the scan result, you may remove the msflxgrd.ocx file.
Warning: While the core functions of Provisioning Manager have been observed to work without this file, Broadcom cannot guarantee that every feature or sub-function of the application will remain fully functional.
C:\Windows\SysWOW64\msflxgrd.ocx.If Provisioning Manager is not required for daily operations, install the component on a dedicated, isolated server or virtual machine that is shut down and accessed only when troubleshooting or management tasks are necessary.
If you do not utilize the Provisioning Manager interface, uninstall the component completely from the production server to remove the vulnerable file.