Regarding the newly discovered flaw Microsoft said that it is aware of "limited, targeted attacks" that had taken place, adding that hackers could use a "specially crafted website" to assume control of the user's computer.
"If the current user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system," warned the company.
"An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
The company avoided offering any detail regarding the nature of the flaw, saying only that it existed in "the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated."
It isn't clear whether Microsoft will issue a fix for the flaw for Windows XP users or just for individuals running the more recent Vista, 7 and 8 operating systems.
- Independent