Less than 24 hours old; IE7 gets first bug

Security researchers Secunia have reported the first vulnerability in the newly released Microsoft Internet Explorer 7 browser - less than 24 hours after the final release.

The Internet Explorer mHTML vulnerability, details of which can be found here, involves how the Microsoft browser handles redirection to sound image files using HTML and could, if exploited, lead to unwanted data disclosure.

The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.

There is no patch yet available at this time. The suggested workaround is to disable active scripting in Internet Explorer. Steps can be found here and here for all the versions of IE.

IE 6 is also affected by same vulnerability. Please make sure to disable active scripting as well if ur still using IE6. Or you better switch to Firefox :)