Fortunately, it seems, we needn't wait for a Microsoft patch to set this right...we can do it ourselves:
Go to Tools -> Options, click the security tab, then click on 'Custom Level'
Scroll down until you find 'Navigate sub-frames across diffrent domains'; set it to prompt or disable.
The test fails if you set it to disable, and it will ask you if its allowed (to exploit you) if you set it to prompt.
I tried it and it works...guess i'll let this setting stay for a while (and wonder if some websites fail to render due to this setting). Better safe than sorry, right!
hmm...sure is IE vulnerable..boy! am i glad firefox is good..