A Windows code-execution zeroday exploit is under active attack, according to Microsoft. The vulnerability lies in the Windows Adobe Type Manager Library ATMFD.DLL and can be exploited by embedding Type 1 fonts into documents. Disabling the Windows WebClient service can block the most likely remote attack vector. Local, authenticated users can also run malicious programs to exploit the vulnerability.