Microsoft hasn't fixed
a critical IE8 security flaw that was reported to the company back in October 2013, according to an advisory published yesterday by HP's Zero Day Initiative (ZDI). The bug was discovered by Belgian researcher Peter Van Eeckhoutte. According to the report, the bug allows an attacker to execute malicious code on computers running IE8 when users visit a website designed to exploit it. This could be done by sending the victim an email or instant message that, if clicked, would lead to the attack.