A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a use-after-free error in the Microsoft HTML Viewer library "mshtml.dll" when processing certain JavaScript event objects, which could allow attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
VUPEN confirmed the vulnerability on fully patched Windows XP SP3 and Windows 7 systems with Internet Explorer 8.
Note: This vulnerability is currently being exploited in the wild.