Security researchers have disclosed a zero-day vulnerability in the latest version of Firefox that gives miscreants complete control of Windows-based computers when the Mozilla browser visits a booby-trapped website.
The vulnerability resides in the way Firefox handles uniform resource identifiers, the protocols that allow the browser to access software and other resources located on a PC. The browser fails to properly vet at least five different URIs, a flaw that could allow an attacker to install malware on a PC simply by convincing a victim to click on a doctored link.
Read the full article at The Register.
http://www.theregister.co.uk/2007/07/25/critical_firefox_vuln/