Microsoft has taken the unusual step of warning users about a serious computer security hole it hasn’t yet fixed.

The vulnerability disclosed on Monday affects Internet Explorer users whose computers are running Windows XP or Windows Server 2003.

The “hole” allows hackers to remotely take control of victims’ machines. The victims can become infected by merely visiting a website that’s already been hacked.

Experts warn that criminals have been utilizing this vulnerability for almost a week. Thousands of sites have been hacked to serve up malicious software that exploits the vulnerability. People are lured to these websites by clicking a link in spam e-mail message.

The so-called “zero day” vulnerability disclosed by Microsoft affects a part of its software used to play video.

Microsoft is urging vulnerable users to disable the problematic part of the Internet Explorer software, which can be done from Microsoft’s website, while they work on a “patch” for the problem.

Get Blippitt via RSS feed, Facebook, Twitter, Google+,
and be sure to get our Daily Email Broadcast.