a new IE-Hole allows a website to write a exe-file to the local disk. It's even possible to replace a welll known exe (like mplayer) and then by suppling a media-file start the new file. As to now there is no patch for this hole (except using an alternative browser
)
a german description and demo of the bug can be found here:
http://www.heise.de/security/dienste/browsercheck/demos/ie/e5_21.shtml

a german description and demo of the bug can be found here:
http://www.heise.de/security/dienste/browsercheck/demos/ie/e5_21.shtml