You gotta love Microsoft!
I was reading the SoCal mailing list and Spun0ut posted the newest of my favorite bugs to come out of the belly of Microsoft. What this exploits is just the fact that the browser will execute scripts that are named.img and take control of the computer. I tried to get it working on other platforms but so far I have only seen it work on XP and 2000 server. Try it yourself, it is located at
http://moloch.org/xp_rules.jpg