Microsoft [Friday] warned Windows users of a new unpatched vulnerability that attackers could exploit to steal information and dupe people into installing malware.
…
In lieu of a patch, Microsoft recommended that users lock down the MHTML protocol handler by running a “Fixit” tool it’s made available… from from Microsoft’s support site.
via Microsoft warns of new Windows zero-day bug in Network World