Microsoft recently issued the monthly security bulletins for March, but absent from it was a fix for the MHTML vulnerability.
In its March Patch release, the company said that it was “monitoring the threat landscape” and “working to provide a solution through our monthly security update release process,” suggesting that the company would not do an out-of-cycle security patch to plug the MHTML hole once a fix is available.
Sure enough, the threat landscape has shown signs of this vulnerability being exploited in the wild, as reported by Google:
We’ve noticed some highly targeted and apparently politically motivated attacks against our users. We believe activists may have been a specific target. We’ve also seen attacks against users of another popular social site. All these attacks abuse a publicly-disclosed MHTML vulnerability for which an exploit was publicly posted in January 2011. Users browsing with the Internet Explorer browser are affected.
While this vulnerability remains unpatched, there is a FixIt tool available which should be applied until further notification of a patch from Microsoft.