IE6 SP1 on Windows 2000 SP4.
IE6 and 7 on Windows XP, Server 2003, Vista, and Server 2008.
The advisory from the company states, “It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code.”
Source: InformationWeek

Articles
Blogs
Kits
Forums