Risk: High
Microsoft released its January patches and updates, but didn't supply one for zero-day flaws that are being actively exploited. Details of the first confirmed Vista flaw have been posted on an underground Russian hackers' website, another flaw that hasn't been patched in the latest Microsoft bulletins.
Four bulletins were issued, three of which were classified by Microsoft as 'critical'. The 'critical' updates address remote code execution vulnerabilities found in Excel, Outlook and IE, whilst the 'important' flaw is a remote code execution vulnerability found in the Brazilian Portuguese MS Office grammar checker.
The full MS advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms07-Jan.mspx