Forum Moderators: phranque
Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address and status bars, which is different from the actual location of the page.
Here [secunia.com]
Not sure if this has been posted or not.
Both the status bar on the link as well as the address line can be easily spoofed. As long as the links on the spoofed site are relative (not using the domain name) the address line shows fake address.
It's got a buffer overflow vunerability, memory leak problems, and a "liveupdate" backdoor that people didn't notice at first. Not a good thing and I hate how this only encourages long delays by Microsoft.