Security researchers have identified yet another zero-day vulnerability that affects Internet Explorer 8 and targets users of almost all versions of Windows.
The vulnerability was discovered as part of the HP Zero Day Initiative in October 2013 and reported to Microsoft. However, the company did not take any action to address it, and the researchers decided to issue a public advisory informing users about the issue.
A Microsoft spokesperson confirmed the existence of the security flaw in Internet Explorer 8, but noted that no consumers have been affected to date, and that the company is currently working on a patch.
"We are aware of the publicly disclosed issue regarding Internet Explorer 8 and have not identified any security incidents that affect our customers. We are diligently building and testing each fix as quickly as possible. However, some patches are more complex than others, and we must examine each one, with a huge number of programs, applications, and different settings.".
"We continue to work to address this issue and will release a security update when it is ready to help protect users. We encourage our customers to upgrade to a modern operating system, such as Windows 7 or 8.1, and run the latest version of Internet Explorer for additional protection," the Microsoft spokesperson said.

