A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an invalid pointer reference in the data binding function which could cause an object to be released without updating the array length, leaving access the deleted object's memory space, leading to arbitrary code execution.
Note: This vulnerability is being exploited in the wild.