Sophos has posted an article today about an announcement by Microsoft regarding a publicly disclosed vulnerability that exists in its Internet Explorer (IE) software versions 5 through 8.

The users who are not running Protected Mode, which is disabled by default in IEs for Windows XP are the ones who are at risk since the mode is enabled by default in Vista and 7.

No patch exists at the moment and users can protect themselves by making sure that the mode is enabled when using the web browser.

Source: Sophos