(January 27, 2012)
Researchers have detected an in‑the‑wild attack that exploits a
known flaw in Windows Media Player (WMP). Microsoft released a fix
for the vulnerability on January 10, 2012 in the MS12‑004 security
bulletin. The attack tricks users into opening a maliciously crafted
MIDI file. It is being called a drive‑by download attack. The malware
attempts to download a Trojan horse program onto the computer. The
Trojan appears to have rootkit capabilities.
http://www.computerworld.com/s/artic...?taxonomyId=17
http://www.zdnet.com/blog/security/h...rability/10213