IE YASH (Yet Another Security Hole)

this article at ZDNet


This is about the ability of IE to run ActiveX 'applets' via raw HTML. IMHO - M$ seems to think its OK for anonymous users to have full access to your system services without contraint. My problem is that people don't seem to care.