There is an unpatched vulnerability in Real Player:

http://www.theregister.co.uk/2008/03/12/realplayer_bug/

Not MS software I know, but it does need IE and ActiveX. It leaves people open to drive-by attacks.