A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a user-after-free error in the Internet Explorer Peer Objects module "iepeers.dll" when processing certain data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
VUPEN confirmed the vulnerability with Internet Explorer 7 on a fully patched Microsoft Windows XP SP3 system.
Note: This vulnerability is being exploited in targeted attacks.