It can allow hackers to remotely take control of victims' machines. The victims don't need to do anything to get infected except visit a Web site that's been hacked.
Security experts say criminals have been attacking the vulnerability for nearly a week.
Microsoft says it's working on a "patch" -- a software fix. Until that's released, the company is urging vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site.
QUICK HEADLINES | MORE TECHNOLOGY | GET NEWS ALERTS
-----------------------------------------------------------------------------------------------
ABC13 SOCIAL NETWORKING
Find us on Facebook | Follow us on Twitter | More social networking
-----------------------------------------------------------------------------------------------
MORE FROM ABC13
ABC13 widget | Most popular stories |
Street-level weather
ABC13 wireless |
Slideshow archive |
Help solve crimes
-----------------------------------------------------------------------------------------------