A compromised site containing a modified GIF file exploits an XSS vulnerability in IE. The GIF file contains an embedded iframe pointing to a malicious site. The site is currently presenting a file not found error message. Microsoft has called the GIF vulnerability a ‘feature’ rather than a vulnerability. We’ve contacted Microsoft again hopefully theyll reconsider their position on this issue. Weve contacted them again hope they’ll reconsider their stance on the XSS issue.”]
Source: https://securelist.com/ie-feature-exploited-itw/30435/