Microsoft Security Advisory (943521)
URL Handling Vulnerability in Windows XP and Windows Server 2003 with Windows Internet Explorer 7 Could Allow Remote Code Execution
Published: October 10, 2007
Microsoft is investigating public reports of a remote code execution vulnerability in supported editions of Windows XP and Windows Server 2003 with Windows Internet Explorer 7 installed. We are not aware of attacks that try to use the reported vulnerability or of customer impact at this time. Microsoft is investigating the public reports.
This vulnerability does not affect Windows Vista or any supported editions of Windows where Internet Explorer 7 is not installed
More info at http://www.microsoft.com/technet/security/advisory/943521.mspx
Oh great. I'm convincing users to upgrade to IE7!