Microsoft is investigating a proof-of-concept exploit code that affects Internet Explorer versions 6 and 7. Here are the affected operating systems:

IE6 SP1 on Windows 2000 SP4.
IE6 and 7 on Windows XP, Server 2003, Vista, and Server 2008.

The advisory from the company states, “It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code.”

Source: InformationWeek