Remote code execution in itunes for windows
A “binary planting” vulnerability in Apple iTunes for Windows allows local or remote (even Internet-based) attackers to deploy and execute malicious code on Windows machines in the context of logged-on users.
Further details can be found here
HDMoore (Chief Security Officer at Rapid7) has also hinted that this vulnerability also affects 40+ Windows applications via this message.