Microsoft Confirms Internet Explorer 6 and 7 Vulnerability
by Don Fosen on Nov.24, 2009, under Security Updates
Microsoft has confirmed that there is a bug in IE 6 and 7 that allows a Web site based hacker to take control of a PC and install malicious code. Internet Explorer 8 is not affected. I highly recommend that if you must use Internet Explorer that you upgrade to IE 8. I personally prefer Firefox which although not perfect is much more secure.
Additional information:
Microsoft Security Advisory (977981)
Microsoft confirms IE6, IE7 zero-day bug
Microsoft Warns of IE Vulnerability