Zero day Java flaw opens up all users to attack

Security researchers have warned of a flaw in Java that could allow malware writers to inject code onto user’s XP or Win 2000 machines by visiting a compromised web site. http://www.itnews.com.au/News/171833,zero-day-java-flaw-opens-up-all-users-to-attack.aspx

Microsoft page on it: http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Exploit%3AWin32%2FCVE-2010-1885.A

and on
http://www.microsoft.com/technet/security/advisory/2219475.mspx
they say: “Microsoft is investigating new public reports of a possible vulnerability in the Windows Help and Support Center function that is delivered with supported editions of Windows XP and Windows Server 2003. This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser or clicks a specially crafted link in an e-mail message. Microsoft is aware that proof-of-concept exploit code has been published for the vulnerability. Microsoft is also aware of limited, targeted active attacks that use this exploit code. ”

To fix the problem go here: http://support.microsoft.com/kb/2219475