Active X does have vulnerabilities and is used to install malware in some cases. Best precaution is not to have your settings to install Active X automatically and to have your computer prompt you first.
Most of the malicious Active X controls come from visiting websites. If you visit a website that you are uncertain or suspicious of and it prompts you to install an Active X control, you are best to refuse it.
To set your computer to prompt you, and you use IE:
- Select Tools, then Internet Options from the menu at the top of the Internet Explorer window. The Internet Options window will appear.
- Select Security from the list of tabs at the top of the Internet Options window. The Security tab will appear.
- Select the Custom Level button. The Security Settings window will appear.
- Scroll down to the Download signed ActiveX controls entry and select the prompt radio button.
- Scroll down to the Run ActiveX controls and plugins entry and select the enabled radio button.
- Select the Apply then OK button to accept the changes
You may need to reboot for the settings to stick.
You can also take the url of the website you are visiting and running a check on it using Site Advisor from McAfee. Just copy and paste the url of the site you are visiting into the "Look up a site report" box of the webpage below
http://www.siteadvisor.com/