Security researchers have identified yet another zero-day in Internet Explorer, which puts users at risk by making their computers vulnerable to attacks.
The vulnerability was discovered in October as part of HP's Zero Day Initiative (ZDI). Researchers notified Microsoft of the issue, but the company has yet to release a patch.
This vulnerability affects Internet Explorer 8 and targets users of almost all versions of Windows, including Windows XP.
According to an advisory issued by ZDI, the vulnerability occurs when the browser handles Cmarkup objects, and could allow an attacker to easily execute arbitrary code on a target computer.
For hackers to exploit the vulnerability, however, user interaction is required, who would have to open a malicious file or view a specially crafted website with IE.
At present, Microsoft has not released any update to address the vulnerability, instead recommending that users take some measures for their own security by changing their browser settings:
Setting the Internet security zone to “high” to block ActiveX Controls and Active Scripting, installing the Enhanced Mitigation Experience Toolkit (EMET), which makes exploiting vulnerabilities more difficult, and configuring IE to ask for permission before running ActiveScripting (or even disabling it completely).

