Flaw in SignKorea's ActiveX

OK, I know you're probably not from Korea, but bear with me here for a second. I found this one from this Secunia article. It's fun for a number of reasons. The first is of course because Korea is always good for a few scattered reports of ActiveX vulnerabilities. You see, the entire country's Internet sites run on ActiveX which makes for a lot of targets, and a very vulnerable population. The second reason is because the listed solution to the ActiveX buffer overflow, is "Update to the latest version." but they don't even provide a link to the latest version, or even SignKorea's website. :) So, after looking up their website, the third reason this one is fun, is because SignKorea is a major Korean certificate authority! It looks like the reason Secunia didn't list a link to the remediation, is because SignKorea's website doesn't make it at all apparent how to update to the latest version of the affected dll. There is one very obscure link labeled "Certificate Issue/Management Installation Program" which I think might be it, but it's really anyone's guess. However, I'm luckier than most as I have my own handy dandy Korean translator on call. (Thanks dear!) So I verified that there is no buried update link on the Korean language site either. :)