Thanks jpwone, that's interesting to know. We allow html code in all our posts and so linking to an external activex object from an iframe therefore becomes a possibility. Though I'd stil expect some sort of prompt to appear, but as I'm not that experienced on activex objects I'll certainly need to read up on it.
We could either turn off all html, but I'm aware that some members make use of it to format tables of information, or try to restrict certain html tags like iframes from posts, that's an option, but it would require some technical work (as there's no easy way to do this at present).
I intend to monitor the situation, whilst it's unacceptable to allow the site to be in any sort of position where it can cause harm to users - I'm also aware that this type of this is rare (in 3 years this is the first exploit that I've come across). Still if it's happened once, it can happen again. 🙁
Apologies to rezo for any inconvenience caused.