Multiple sites have been observed hosting pages which exploit this vulnerability. Microsoft has released a Microsoft fix it as a temporary mitigation for this issue on systems which require IE8. Users of IE8 who cannot update to IE9+ are urged to apply the Fix It immediately. An exploit for this bug is now publicly available within the metasploit framework. The payload itself is base64 encoded within a web page. This is sometimes used in an attempt to evade detection. On the victim machine the browser will automatically decode the payload and will be exploited.”]

