This has been getting a bit of attention lately on the Interweb. It's a serious flaw in the way WMF (metafiles) from websites are handled (from images, as I understand it). There are apparently already 50 known exploits in the wild, and the number is sure to grow.
Link to the Microsoft Security Advisory on this issue
http://www.microsoft.com/technet/sec...ry/912840.mspx
The "suggested actions" from MS may not be enough, however. A recent (i.e., 1 January) special episode of the Security Now podcast (with Steve Gibson and Leo Laporte) (download here
http://aolradio.podcast.aol.com/sn/SN-020SE.mp3) points to a fix offered here:
http://www.hexblog.com/
I've installed and seems to be fine (i.e., no system instability).