The vulnerability is located in the ATL::AtlIPersistStream Init_Load function in msvidctl. The exploit code will load a malcrafted GIF file to trigger the vulnerability. Vulnerability ID is CVE-2008-0015. There is no patch yet for this vulnerability, but there are some workaround instructions from Microsoft until a patch can be issued. The first compromised domains mainly originating in China are used in the spread of this new zero day. As the vulnerability is very dangerous and very easy to exploit, we strongly suspect it will spread further and swiftly.”]
Source: http://securitylabs.websense.com/content/Blogs/3434.aspx

