Back in February, Microsoft silently slipped Windows Presentation Foundation plugin into Firefox without user’s consent. This plugin came along with .NET Framework 3.5 Service Pack 1 and was installed in IE as well as Firefox via Windows Update. It has now been discovered that the code in the plugin can cause a very serious vulnerability in Firefox, which will potentially expose users to "browse and you’re owned" attacks.
View original here:
Microsoft’s Plug-in puts Firefox Users at Risk