Microsoft issued a security advisory on Friday for a vulnerability that was discovered last week. They have also released a "Fix It" that can be accessed from their knowledge base.
This is another one of those Windows bugs that would likely be exploited by sending an email or posting to a forum with a link to a malicious site. As always, my advice is that if you get a link in an email (even if it appears to be from a friend) verify that they sent it before clicking on it, and use caution when clicking on links from Twitter, Facebook, or other social networking forums.